Yes, the windowing system requires such to prevent applications with less privileges spying or controlling those with more.
On X, it is possible for an exploit in a browser to gain root if you have an application opened as root.
Although such exploit would be extremely difficult to pull off, state actors will do anything for specific targets.