Comment by jdougan

17 hours ago

I wonder if this could be practical for controlled environment devices like game consoles.

What do you mean? By the time you have kernel access like that you’ve already won.

  • I suppose the theory is when you're attacking a console like the Xbox One with some known hypervisors vulnerabilities, but generally what is considered to be secure hardware, you could use the patchable hypervisor vulnerability to install your custom OS, then use the OS itself to find silicon bugs, finally securing a pathway for permanent access to the device.

  • It’s practical in the sense that it lets a researcher find additional silicon bugs, although most game consoles now use merchant archs anyways