As with many matters in this world, there is no possible black/white assessment, and therefore no black/white answer. 'Safety' in this context has at least three broad components, which can be called something like structural, organizational and personal.
Is it possible to introduce malware to the memory and/or storage by means of a remotely-controlled attack, as opposed to a random attack through removable media? Failing isolation from all networks and avoidance of all unproven removables, the answer is 'Yes'. However, the risk can be minimized.
Can malware control the operation of the computer? If the operating system is accessible to all applications, or if it can be circumvented by direct address of the hardware, again the answer is 'Yes'. If core operations are controlled by a single application, which is at least one remove from the user's voluntary control and which will respond only to permissible requests, again the risk can be minimized.
The most vulnerable component is the personal. If connections, firewalls, permissions and passwords (as symbols of the kinds of protective measures) are not implemented, or worse are circumvented by users, only the intrinsic strength of the organization of the OS can offer protection against malware. The curiosity, cupidity, complacence and ignorance of users, however, are powerful aids to would-be attackers.
No platform is free of users unless it is embedded, so the answer to your question has to be along the lines of 'It depends ...'.
de
(60x) 13DT + 3PB + PTPro; (G3) 7DT/MT; (G4) 3T + PB. System 8.1 to OS 10.5.8