Both Kernel and userland
Android runs a linux kernel yes but is very far from normal linux distros, it almost alleviate all of problems with linux
Hurd kernel’s concept seems solid but it doesn’t look like actively developed?
OpenBSD might be best choice as you say at least until Genode or something similar become useable
As I mentioned in post Kicksecure plans to harden Linux but is not there yet, For virtualization and containerization there is QubesOS but still that doesn’t seem ideal and it requires some beefy hardware
MacOS’s security is great but unfortunately not open source
QubesOS’s sandboxing/virtualization is way above whatever you can do on Debian