You should worry, system users are relied on to effectively separate privileges even in "single-user" desktops. This has led to privilege escalation before, not to mention the potential for browsers to access these ports [0].
That said, a random password should be enough protection, even if it isn't the cleanest solution.
[0]: e.g. https://palant.info/2020/06/22/exploiting-bitdefender-antivi...
I do wish gRPC allowed for easy usage of UNIX domain sockets and perhaps named pipes, however. Sometimes all you need is IPC, but in my case, I'm happy to have remote usage builtin.