What about hypervisor as microkernel and VM as app? Is this a viable new model for system security?
Remember software engineers have been stamping out bugs in the x86/64 arch for decades and they still find new bugs all the time. ARM arch is no different, they'll be stamping out bugs for decades too. By adding a hypervisor and virtual machines you're layering a whole new set of bugs on top like a bug sandwich. Complexity skyrockets, security is the first casualty.
As for not having root on a proprietary device it's a double edged sword. On one hand you're firmly in the land of feudal security leaving everything up to the developers, on the other hand if you root the device you're now opening up priv escalation and NFC exploits galore.