Exploits for the Tegra X2
  • Rust 99.7%
  • Shell 0.3%
Find a file
2026-01-03 01:51:49 +01:00
ml1hax Initial release 2025-12-29 14:19:44 +01:00
rcmhax feat: use sehax to recover used FEK from RCM 2026-01-03 01:51:49 +01:00
writeups Initial release 2025-12-29 14:19:44 +01:00
.gitignore Initial release 2025-12-29 14:19:44 +01:00
README.md Initial release 2025-12-29 14:19:44 +01:00

tx2hax

Overview

This repository contains implementations of several exploits for vulnerabilities for the Tegra X2.

The rcmhax folder contains an exploit implementation, and a sample payload, for getting code execution inside the BootROM of Tegra X2's via the USB Recovery Mode.

The ml1hax folder contains implementations of sparsehax and dtbhax for Magic Leap One headsets.

Writeups

There are text based writeups available in the writeups directory, specifically:

And additionally a talk at 39C3.