This repository contains implementations of several exploits for vulnerabilities for the Tegra X2.
The rcmhax folder contains an exploit implementation, and a sample payload, for getting code execution inside the BootROM of Tegra X2's via the USB Recovery Mode.
The ml1hax folder contains implementations of sparsehax and dtbhax for Magic Leap One headsets.
There are text based writeups available in the writeups directory, specifically:
And additionally a talk at 39C3.