This is a historical accident; only toy and mobile OSes have any sort of application-level access control.
Wrong, they can just add DRM.
Wrong, they can just add DRM.