Earlier quoted context omitted.
This seems to be by design: when these things are available, spyware -- especially on Windows -- will be quick to make malicious changes in all these if they can. It's a pain, but I can see the compromise. If it makes the average Firefox user more vulnerable, there's definitely a case to protect them, even at the expense of its more capable users.
No software trick can fix OS unsafe design. Also "protecting users" limiting their power means jails them, not really protecting. End users are adult, not child, and developers are others adults with ZERO right on their software's user. If people want safer systems better learn to avoid commercial software, nothing else can help them.
Perhaps a more fine-grained permission model is needed for cross-application changes, but I can't think of anybody actively working on it in an OS.