We've implemented this functionality here:
https://github.com/pfirmstone/jdk-with-authorization
Along with whitelisting serializable classes and URL's, it has a tool to generate polp policy files during deployment, it can even prevent loading unwanted JDK modules, it will be released on the same release schedule as Java 24. We don't have a TCK license at this stage.