From the papers, these two bugs are also exploitable from ARM.
Does it mean a hacked IOS/Android app can also (in theory) sniff the password enter in system dialog as demo in the video?
Realtime password input - https://www.youtube.com/watch?v=yTpXqyRYcBM