Telegram Desktop vulnerability allowed any user's file to generate market data?

My message to the world is that LLMs should be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).