I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.
I guess it also has access to the cookies for all your logins.
The little I have to run Telegram Desktop for, I run in a VM. I'd never let the little oligarch's code touch my desktop OS.
interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.
one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.
Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously.