What they try to patch is the random arbitrary code exec on kernel, not in userland, they moved the way browser manage the memory malloc() and adjust the vbuffering, but they forgot to remove the ERROR, so, this is WHY when it push back to the memory alloc() over the limit, the ERROR give back to exec() at the MP4... so, they ARE STUPID. Also the lib on mp4 should be packed in the new fw, so, someone let it PROPOSITAL inside 5.5.1 to test the hackers to check WHERE TO LOAD and not to GUESS where it is!
On the memory there is a table for, read, load, exec, exec as R, exec as U, so, they let EXEC U and not Exec R....
This mean now nintendo already know how "they" are doing exec on the kernel side, but they DO NOT KNOW how the HACKERS find where to RUN the code (doenst matter signed or not signed) what's matter is HOW THEY FOUND OUT WHERE THE EXEC POSITION ON KERNEL FLUSH IS KNOW!
Hahaha... someone has a nintendo debug unit out of the nintendo shelf... or they had the IOSU debug on hands.... do you know ICE nintendo???