yup
DS Settings now boots SAFE_FIRM instead of NATIVE_FIRM now
So what ? Whatever firmware mset runs on top of has nothing to do with mset itself, the question is: Is mset still exploitable ?
A lot of people claim the mset vulnerability hasn't been fixed in 6.3.x presumably because changing the lenght value still makes it crash, but a crash doesn't necessarily mean an exploit.
There are plenty of ways Nintendo could have fixed the vulnerability itself while still letting mset crash. In fact, if I were them, I'd call the panic function as soon as I detect a lenght that's set too large. I am not them though, so who knows what they did ? Until someone posts actual assembly of the 6.3.x mset or test more than just the fact that it "crashes" I will assume the vulnerability might have been fixed already.
Also should someone exploit SAFE_FIRM, he would most likely gain enough privileges to softload a patched version of NATIVE_FIRM. (though it would require changing the base addresses and so on, so it would be more of a pain, but doable)
That said, there is little hope of someone finding a new NATIVE_FIRM exploitable vulnerability considering how limited people are while using ROP chains in the first place.