"[GNU/]Linux being secure is a common misconception in the security and privacy realm."
https://madaidans-insecurities.github.io/linux.html
"[GNU/]Linux is thought to be secure primarily because of its source model, popular usage in servers, small userbase and confusion about its security features. This article is intended to debunk these misunderstandings".
Based on this, one should try to do as much as possible on a GrapheneOS device
I would say QubesOS is for sure the safest, but having normal sandboxes and permissions should be enough. QubesOS is like making an insecure OS secure, as there are no permissions or portals, so you need to go way beyond and run multiple VMs at a time. This is not suited for any daily use, my modern laptop really struggles to run 2 VMs at a time