The right basic idea is, the UI for "do X to Y" must combine designating which Y you want and giving permission to access that Y (and no other). It's when the OS shell separates these aspects that you have to choose between extra annoying useless permission pop-ups and any security boundaries.
(Yes reworking our all our systems in terms of capability security is a giant job. But there's a difference between a giant job and )