Magic Leap One Bootloader Exploit
github.com
github.com
https://gbatemp.net/threads/switch-2-data-gathering-for-poss...
You never know! People said that about the Switch at launch, and then someone softmodded it with a paperclip and USB-C.
The paperclip was just the easiest way of triggering RCM, which is a standard feature on Tegra. The vulnerability lay in that they didn't bounds check certain types of USB requests properly.
I would have thought they'd do some mixing based on serial number or chip id as a baseline.
Or at least that's what the hash of their SBK implies.
I do enjoy seeing the boot chain on Tegra get broken yet again though.