Yeah but what's to stop me from spawning a hidden instance of edge, sending keys etc to it to get it to visit some page, and using either window sub-classing (to hack it's memory space and read the request directly) or a local proxy server to steal the attestation it generates before terminating the request?
Likewise what's to stop you from patching the operating system directly (ok secure boot)
You could also just emulate an entire windows OS + TPM and have the emulator do it it sounds like
Like any scenario where I'm allowed to run arbitrary code within the OS with administrator privileges sounds like you could escape this.