After some time of Xbox One research, I've finally managed to pop a shell under retail mode. The exploit was ran on older firmware (any version before year 2020 is vulnerable). Note that no custom store apps were used for this exploit.
That's pretty impressive.Any process under System OS is accessible. More reversing is needed to see if XVDs can be decrypted although we'll probably need access to Game OS to do so.