Since many people are using a PDF reader to read PDFs from relatively untrusted sources, do yourself a favor and at least use a reader that does not have full system access.
macOS: Preview.app (uses macOS sandboxing)
Linux: Evince Flatpak on Wayland (Flatpak uses sandboxing. Wayland because X11 apps can read all keystrokes, mouse events, do screengrabs.)
Windows: no clue
All platforms: in-browser PDF reader with a browser that sandboxes.
Flatpak is providing the actual application sandboxing, but being allowed to talk to the X server is a huge amount of privilege that can't really be restricted.
I think UWP apps are sandboxed by default, so something like Xodo PDF could be a possibility.
Edge, firefox and chrome have built in PDF readers.
For more control sites can self-embed pdfjs so no external reader is required.
Addendum: Most links of the bottom row don't work anymore. Needs updates
Top row:
Platform (what's that?): GNU (isn't that some kind of African animal?) Linux (oh, I know that one, it's the cute penguin!)
The rest of the text in those boxes is mostly techno-babble for non-tech users (Gnome? KDE? DjVu?!??)
I understand the intent behind it, but it would only serve a very small niche of users, who can already fend for themselves.
Everyone else would go like: PDF? Ah, that's Adobe!