If you own example.com and want to have cookies accessible in the root (e.g. example.com/login.html) then you can't prevent example.com/users/~evildoer from accessing them.
Don't we have equivalent problems with evildoer.example.com trying to get and set example.com cookies? Hence why Google and Github and other major sites use separate domain for user hosted content vs first party content.
Cookies are a terrible security model in general.
No, but you could redirect your root requests to example.com/home and serve from there with relevant cookies restricted to the /home path.