::
From my research:
1. The short answer is Yes, a Trezor can be flashed to export your private keys, particularly if Satoshilabs chooses to do so.
2. The longer answer is „Yes, but…“ as described by others below. Trezor firmware is open source. Trezor doesn’t use a secure element. Trezor has NEVER CLAIMED that the seed phrase is locked down against malicious firmware or hardware intrusion. Instead, they use transparency (open source, code signing) and disclosure (unsigned firmware warning to guard against this. Whereas Ledger is closed source requiring unverified trust, and has now exposed material misstatements about the security mechanism of the ledger devices.