Perhaps the ability to sign grub.cfg should be added to GRUB2, and this feature should be enabled by default.
Though this would mean rather than allowing users to enter arbitrary kernel boot options (and being able to leverage buffer overflow exploits), a bunch of preset menu items would have to be present. Alternatively, this signed grub.cfg can have its boot menu password-protected. (If I recall correctly individual menu items cannot be password protected.)
Lowering the GRUB2 attack surface area is a good idea, so hopefully these suggestions get deeply considered.