Here is the high-level magic:
But what is OmniUS? And why does it matter more than the temporary root exploits of 2016? omnius bootloader unlock
If the vulnerability is in the (mask ROM), it is unpatchable . The silicon is baked. The only "fix" is to release a new hardware revision (v2 of the SoC). Here is the high-level magic: But what is OmniUS
Note: I am omitting specific hex offsets because they vary by SoC, but the logic is consistent. omnius bootloader unlock
But here is the paradox that keeps security researchers up at night:
This creates a "Schrödinger's Security" state: The device is technically patched in the factory, but user-flashable firmware means the vulnerability is eternal for any device that shipped with it.