Audit overview and executive assessment
Home · Documentation · Findings · Status
This page is a build-25G83 research snapshot. Static code paths and declared capabilities do not establish execution or effective runtime policy. Original raw evidence is retained privately; public tables and measurements are linked where available.
Executive assessment
The strongest current result is exact correspondence with Apple’s distribution for the retained update files that have reference counterparts. All 1,186 corresponding regular files and all three symlinks match. An independently matched installer-integrity file brings exact official-byte coverage to 1,187 of the 1,191 original regular files. The four remaining files are a product index and three boot-label assets, not silently counted as verified vendor matches.
The supplied folder is a staged subset of the complete update. The full reference contains 1,047 additional regular files. Their absence from staging does not establish malicious deletion or explain the update’s history.
| Area | Established result | Practical limit |
|---|---|---|
| Source preservation | All 1,191 original regular-file hashes match the working copy | Logical live acquisition; custody before collection is not established |
| Recursive inventory | 105,123 regular-file paths across seven source/image scopes | Paths are not unique binaries; inventory is not complete semantic review |
| Official distribution | 1,186 matching update files, three matching links, zero corresponding-content differences | Four original presentation/index files lack exact vendor references |
| Executable pages | No mismatch in supported CodeDirectory checks | Resource envelopes, certificate trust and runtime acceptance are separate |
| Image4 | 868 standalone tickets plus one nested ticket verify; examined certificate-role checks pass | Hardware policy, personalization and rollback enforcement remain incomplete |
| EFI | All 69 examined Apple-format PE EFI signatures verify | Product.efi is a separate wrapper; device execution is unobserved |
| PCI EFI payloads | Nine compressed driver images decoded and bounded | No embedded PE certificate tables; outer ROM authentication is separate |
| Ramrod sealing | Examined plugin call enables root-hash validation and propagates errors | Other branches, execution history and effective device policy remain separate |
| Skip control | Official-reference brain maps Boolean DoNotSeal into skip-sealing |
Full caller authorization, all option mutations and historical use remain unresolved |
| Service access | Examined softwareupdated and brain command tables require named Boolean-true entitlements | This is not exhaustive authorization coverage of every endpoint/callee |
| USB proxy | Launch definition exists; its executable is absent in the examined RAMDisk | No listener, USB traffic or remote access was demonstrated |
| Remote attestation | Two embedded roots match Apple’s published fingerprints; conditional DCRT/DAK checks bind an attested key to a selected certificate key | Explicit expiration exception needs further policy review; complete peer authorization remains unresolved |
| Chassis membership | Required-OID producers and two explicit chassis-check exceptions traced | Successful evaluator result does not always establish same-chassis membership; effective policy, AMFDR and input authenticity remain incomplete |
The evidence supports an Apple update/recovery interpretation of the retained content. It does not certify the installed Mac, its firmware, or every implementation as uncompromised or vulnerability-free.
OpenCore has not been established as installed or active by this investigation. The OpenCore links below identify third-party research references used to cross-check Apple keys and binary formats. They are not detections of an OpenCore bootloader in the collected update data. See OpenCore references and what they mean.