Skip to the content.

Audit overview and executive assessment

Home · Documentation · Findings · Status

This page is a build-25G83 research snapshot. Static code paths and declared capabilities do not establish execution or effective runtime policy. Original raw evidence is retained privately; public tables and measurements are linked where available.

Executive assessment

The strongest current result is exact correspondence with Apple’s distribution for the retained update files that have reference counterparts. All 1,186 corresponding regular files and all three symlinks match. An independently matched installer-integrity file brings exact official-byte coverage to 1,187 of the 1,191 original regular files. The four remaining files are a product index and three boot-label assets, not silently counted as verified vendor matches.

The supplied folder is a staged subset of the complete update. The full reference contains 1,047 additional regular files. Their absence from staging does not establish malicious deletion or explain the update’s history.

Area Established result Practical limit
Source preservation All 1,191 original regular-file hashes match the working copy Logical live acquisition; custody before collection is not established
Recursive inventory 105,123 regular-file paths across seven source/image scopes Paths are not unique binaries; inventory is not complete semantic review
Official distribution 1,186 matching update files, three matching links, zero corresponding-content differences Four original presentation/index files lack exact vendor references
Executable pages No mismatch in supported CodeDirectory checks Resource envelopes, certificate trust and runtime acceptance are separate
Image4 868 standalone tickets plus one nested ticket verify; examined certificate-role checks pass Hardware policy, personalization and rollback enforcement remain incomplete
EFI All 69 examined Apple-format PE EFI signatures verify Product.efi is a separate wrapper; device execution is unobserved
PCI EFI payloads Nine compressed driver images decoded and bounded No embedded PE certificate tables; outer ROM authentication is separate
Ramrod sealing Examined plugin call enables root-hash validation and propagates errors Other branches, execution history and effective device policy remain separate
Skip control Official-reference brain maps Boolean DoNotSeal into skip-sealing Full caller authorization, all option mutations and historical use remain unresolved
Service access Examined softwareupdated and brain command tables require named Boolean-true entitlements This is not exhaustive authorization coverage of every endpoint/callee
USB proxy Launch definition exists; its executable is absent in the examined RAMDisk No listener, USB traffic or remote access was demonstrated
Remote attestation Two embedded roots match Apple’s published fingerprints; conditional DCRT/DAK checks bind an attested key to a selected certificate key Explicit expiration exception needs further policy review; complete peer authorization remains unresolved
Chassis membership Required-OID producers and two explicit chassis-check exceptions traced Successful evaluator result does not always establish same-chassis membership; effective policy, AMFDR and input authenticity remain incomplete

The evidence supports an Apple update/recovery interpretation of the retained content. It does not certify the installed Mac, its firmware, or every implementation as uncompromised or vulnerability-free.

OpenCore has not been established as installed or active by this investigation. The OpenCore links below identify third-party research references used to cross-check Apple keys and binary formats. They are not detections of an OpenCore bootloader in the collected update data. See OpenCore references and what they mean.