So if listening on localhost to provide a GUI on the users desktop, is it not meant to be protected from attacks from the web?
This has been an issue for decades and just recently been in the news due to massive attacks against home routers (web apps listening on the LAN) and desktop apps (both web apps and web APIs listening on localhost). I get the impression that this has not been considered.
however, the safety of an application is up to the developer, that can leave opened also the door of a safe atomic bunker
Unless I'm completely misunderstanding I don't agree that is at all comparable with the security model expected of a "standard desktop gui framework" nor safe.
Though indeed if there are large, random and unpredictable IDs required to perform actions it may defeat or make the attack difficult.
My recommendation is you read up on the subject and I'll leave it at that. You have been given everything needed to search for more information.