Nope, it gets access to its own framebuffer that’s composited in the GPU. OS sees a black viewport, and only a black viewport.
The comms is encrypted on the bus using strong cryptography, so you can’t sniff it.
All these software blobs are signed and encrypted, you can’t replace it without the signing key.