I dont wanna start a war over this btw, even though it may not seem :)
On a personal computer, they "can't do much" to the things you can trivially re-create by reinstalling anyway. Apps, system files, etc.
They can however do everything to your own files, steal your documents, bank account data, and more.
That a progran run as you without root "can't do much" made sense for multi-user Unix services, not for a personal computer and your own files.
>Wonder why the most important systems in the world and big tech's servers run GNU/Linux? There's a reason
Yes, and it's not because "unless you log in as root, the apps can't do much" on your personal laptop.
Then don't install apps and use the web, mobile sandboxing is much weaker compared to any modern browser.