This is only applicable if you already have root (in order to get beyond that), right? It doesn't expose new risk of local privilege escalation?
This is more about getting at the code that device manufacturers attempt to hide from the end user. Platform keys, secure enclaves, etc...
Reaching into ring -2 or the TPM allows privilege escalations past traditional "root permissions" and lets attackers defeat the sort of tamper protection that's designed to make escalations to local root manageable. Wipe-resistant malware, falsified cryptographic attestations, all sorts of fun.