I need some time to pursue something I found in the MCP module. If I'm correct about this, we should be able to get a boot-time exploit. The reason for that is that the MCP module is responsible for launching "master" titles (like the PPC kernel, for example) and I found a bug that, if it turns out to be exploitable, should allow to hijack execution while MCP is still preparing to launch stuff. This means, early IOSU access and a direct boot into an exploitable environment. Not to mention that MCP is the IOSU user module with most privileges (next to BSP that is) and having access to it alone is more than enough to own the IOSU kernel at any given time.
With that said, if this turns out to be nothing, I'll release the exploit right away.