People could always use the snap versions of libreoffice/browsers and either limit access to the home directory or remove access to the network. It seems the easiest way of applying a Android permission based model to Linux.
Alternatively, there are also firejail profiles which could be used for restricting what these tools can do.
About a year ago I enabled apparmor with a bunch of additional rules and noticed some odd denied file read attempts.
I asked around and people blamed it on some Java or pgp stuff. No idea if it's still in there, I can't see it anymore but I also may have disabled all libreoffice plugins.
Alternatively, there are also firejail profiles which could be used for restricting what these tools can do.