Thankfully, better designs such as seL4's VMM do exist, although it might need a little more work [1] until usable for the purpose.
I do not think so.
It's a pretty deep rabbit hole if you really want to go down it. You can make a case for not trusting any CPU that you didn't design and fab yourself, and even then you have to watch out for your own mistakes and bugs that can be used against you.