No, it's definitely a Telegram specific vulnerability. It might be worse because of poor defense in depth, but without Telegram itself being vulnerable it wouldn't matter.
Does Telegram do that, or do they consider themselves beyond bugs, just like they consider themselves too clever and untouchable by anyone to need end-to-end encryption?
not true on macos.
So how will you spam all the group chats you're on with meme gifs downloaded from facebook then? :)
The file-manger application managed above is a single point of failure, of course. So, it should be allowed to use only one provided by OS vendor.
There is a lot of middle ground, like having a shared folder for access. "Downloads" might be a good default, if clearly communicated, that anything in there, is accessible by any app.
Uhm, OpenBSD would like a word, buddy.
[1]: https://github.com/containers/bubblewrap#usage
[2]: https://man.archlinux.org/man/bwrap.1
[3]: https://wiki.archlinux.org/title/Bubblewrap#Usage_examples
[4]: https://wiki.archlinux.org/title/Bubblewrap/Examples#p7zip
Not all user processes upload those files somewhere surreptitiously.
Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.
Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.