An OS should be really resistant to this kind of things.
That would have prevented a bad driver from taking down a device.
The system volume is signed by Apple. If the signature on boot doesn't match, it won't boot.
When the system is booted, it's in read-only mode, no way to write anything to it.
If you bork it, you can simply reinstall macOS in place, without any data/application loss at all.
Of course, if you're a tinkerer, you can disable both, the SIP, and the signature validation, but that cannot be done from user-space. You'll need to boot into recovery mode to achieve that.
I don't think there's anything in NTFS or REFS that would allow for this approach. Especially when you account for the wide variety of setups on which an NTFS partition might sit on. With MBR, you're just SOL instantly.
Apple hardware on the other hand has been EFI (GPT) only for at least 15 years.
If something cannot be formally verified at the machine code level there should be a controls level verification where vendors demonstrate they have a process in place to achieving correctness by construction.
Driver devs can be quite sloppy and copy paste bad code from the internet, in the machine code Microsoft can detect specific instances of known copy and pasted code and knows how to patch it. I know they did this for at least one common error. But if I was in the business of delivering an OS I want people to rely on my OS this stuff formal verification at some level would be table stakes.