These are all improving: hardware support is generally getting better and guests modified to behave nicer so weird cases can just fail, and devices are often now specifically designed for virtualization (plug for my old project VirtIO here!). But it's still software, and asserting there are no bugs left seems incautious.
The information leakage problems are an ongoing whack-a-mole which depends on your setup: they may or may not result in escapes, depending on the nature of the secrets.
Of course, higher level bugs are still there: convincing people or software to change settings, install software or pass too much information through existing channels which are perfectly secure!
See also my answer to the sibling.
> and asserting there are no bugs left seems incautious
I don't exactly assert there are no bugs. I do assert that escalation to the host is very unlikely, since I've never seen one after Blue Pill: https://en.wikipedia.org/wiki/Blue_Pill_(software)
> handling the guest instruction traps on the host side which can actually get quite hairy in corner cases
Any examples, where a Disposable VM can make some harm to the host?
-- they're rarely discovered. But they have existed, more likely currently exist or will exist. Certainly way better than not having that protection, but running sketchy binaries is still not the best idea!
There were no escapes since Qubes switched to VT-d (release 4.0) in 2018.