Amusingly, Linux solved that with flatpack.
Applications are installed in their own sandboxed containers and you decide which files they can and can’t access.
The Linux desktop has some very interesting pieces of technology.
Apple could do the same on macOS but that would pierce the veil that their user hostile policies are actually motivated by greed and not security.