The answer is no.
1. Only authorized and authenticated software can run on the console. If unauthorized or unauthenticated software is found to run on the system It the software can be disabled automatically or the console itself can be made untrusted.
2. Software only can run in a particular virtual machine. It doesn't have the ability to cross over virtual machines or infect the HyperV OS.
3. The Xbox One has the capability to reset the virtual machines back to a set point. Essentially there is a shadow copy of the two virtual machines. If they become untrusted, the console has the ability to reset and reapply the vm copy.
4. The Game OS and the HyperV OS are both highly specialized OSes that are locked down. The Apps OS is the only "open" OS and even that is locked down. Remember, the Apps OS is similar to Windows RT.







