I think this assumes that all OS designs have equivalent levels of security, but if this is true then why are there security-focused operating systems like seL4? Also I think that without the backwards compatibility requirements of Linux, one could probably have features that improve security (eg sandboxing of some kind)