I dumped my sysNAND and my XOR Encryption with Decrypt9, i injected fbi into the H&S app and then re-wrote the modified image onto the nand.
You can follow this guide which is pretty straightforward:
https://gbatemp.net/threads/release...ect-generator-jpn-usa-eur-chn-kor-twn.391525/ but watch out: you need to write to sysNAND. A failure will result in a brick (it worked like a charm to me)
I even succesfully installed the browser without passing through the sysupdater (the cia is available on that iso site and it works well)
[EDIT]Everything works! As a reference for the future generations:
1) Upgrade sysNAND to 9.0.2-0 via cart
2) Use Ninjhax2 with the code for 9.0.2-13
3) Launch Decrypt9 from Ninjhax to dump sysNAND and XORpad
4) Inject FBI into the dump and write it to sysNAND using Decrypt9
5) Launch PastaCFW from Ninjhax, then Healt&Safety APP and then install the browser's CIA downloaded from that iso site
6) REBOOT! It won't work if you don't reboot (i lost half an hour before figuring it out)
7) Now you have an exploitable browser.