File paths will be relative to the correct sandboxed folder as long as you get them via system.pathForFile("file.txt", directory_enum), with directory_enum being system.DocumentsDirectory, system.ResourceDirectory, etc.
Otherwise, I just had the exact same "permission denied" problem, even though I AM using Corona. So the problem was that before the io.open call that returned an error, I had another io.open call, that was meant to read the same file, but the file handle wasn't closed after that.
So, to put it simply:
io.open(path, "r")
...
io.open(path, "w") --ERROR! this one returns a nil handle and a "permission denied"!
To fix it do the following:
local fh = io.open(path, "r")
...
io.close(fh) --close the file after finishing with it
...
io.open(path, "w") --now the file is closed and can be opened again