Regarding Windows all I read is that this “admin permission dialog” is launched in some form of sandbox where no software can access it. Not sure about faking input devices though, and I am also not promoting Windows for Security
Nearly all tools (with flatpak and portals progressing into better directions but probably never finished) have rw permissions everwhere.
The modern OS threat model is not other users, as private users mostly have single user systems. It is malware and software doing nasty things.
On Linux this always worked out somehow, but grabbing your sudo password is not hard, just alias sudo to a script reading your argument, reading your password, and piping the password to the real sudo. You dont even notice it but that script just got your sudo password.
No way, if you dont already have that, its a complete waste of money. 300€ is not little! I bought a Clevo NV41MZ for that, which has 16GB RAM, 500GB SSD, i7 CPU and is supported by Coreboot
If you can run the Raspberry Pi Desktop that would be good. Wayland and I think very light.
I am thinking about installing that on Fedora, rebranding and all, to have an actually small Wayland Desktop, because the current options are either WMs or bigger Desktops