It has to with the secure processor. Although you seems to ignore what is the TCB.
No, this only works on the regular processor cores. It's a cache timing attack that depends on the attack code and the targeted cryptographic code running on processors that share cache.