Why a hotspot instead of a USB 4g modem? Concerned about 4g hardware/driver vulns but not WiFi hardware/driver vulns?
Edit: yes, I guess you're concerned about sim-resident malware exploiting the modem, exploiting the rest of the machine via USB.
Also, if you're that paranoid, you should probably be running something seL4-based to better compartmentalize compromises.