Docker containers can sandbox GUI apps[0], but I don't know if it's secure enough. Maybe not.
https://zeltser.com/security-risks-and-benefits-of-docker-ap...
The isolation provided by Docker is not as robust as the segregation established by hypervisors for virtual machines.
As seen with CVE-2015-3629[0] for instance.
The other points: patch level and docker management isn't understood, seem to be people problems which can easily be corrected.
[0]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3629