Things will get even worse because Google is working on the AVF framework which includes so called "protected VMs" - of course they're meant to be protected from you, the user. Their "security" (where you're the "attacker") is based on the TEE but also a so called "protected vm firmware". In their design document they explicitly say that these protected VMs can provide "security" only with locked bootloader.. you probably know what that means..