Why not use filesystem permissions/ACLs on named pipes to access native interfaces (as a poor-man's microkernel)?
Hypervisor overhead for hardware-assisted virtualization is worse than OS-level preemptive threading? Why bother with an OS at all and just run mobile apps in a hypervisor with system service ACLs?