If the OS is working properly, the havoc should just result in "permission denied."
If there's a path on the system that the user should not be able to read, that's the job of the OS to handle, not the individual applications.