Skip to the content.

Findings index

Home · Documentation · Evidence

This index preserves every one of the 100 finding IDs in the audit snapshot. Status is the original ledger wording. Evidence level describes the scoped observation, not a claim of runtime execution or whole-object closure. Full claim, evidence, and limits appear in each linked record. The CSV ledger preserves the original fields. The source crosswalk records a retained audit document and location for each ID. A section-context match is identified separately from an explicit ID mention. Public derived datasets are related measurements, not substitutes for the retained originals.

ID Title / scoped claim Subsystem Status Evidence level Retained source location
REF-001 Exact Apple catalog product 140-93587 identifies 25G83 Reference and provenance confirmed VERIFIED (bounded static or measured observation) STAGE2_COMPARISON.md:5
REF-002 Retained installer integrity metadata equals Apple-hosted metadata Reference and provenance confirmed VERIFIED (bounded static or measured observation) STAGE2_COMPARISON.md:5
REF-003 All 42 J160AP preflight component digests match local manifest Reference and provenance confirmed VERIFIED (bounded static or measured observation) STAGE2_COMPARISON.md:61
REF-004 1186 staged update files and three symlinks match exact official archive Reference and provenance confirmed VERIFIED (bounded static or measured observation) STAGE2_COMPARISON.md:19
RAM-001 Examined patch-plugin sealing call binds to main ramrod and enables root-hash validation RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:50
RAM-002 Root-hash code requests xsys despite xmtr diagnostic text RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:76
RAM-003 Update.plist supplies typed skip-sealing and system-volume-verify-done controls RAMDisk, ramrod, and brain partial VERIFIED (partial scope); interpretation open STAGE4_RAMROD.md:104
RAM-004 Ordinary loader path does not enter manifest or NVRAM override parser RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:119
RAM-005 All 27 examined softwareupdated command-table entries require a named Boolean-true XPC… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:145
RAM-006 Official-reference brain writes Update.plist; typed DoNotSeal feeds skip-sealing; writer… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:184
RAM-007 Brain seven-command table requires named Boolean-true entitlements; gated PingService returns… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:217
RAM-008 Static NSXPC receiver has returning prepare/apply bodies; separate gated command route has… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:236
RAM-009 Verification-state flag set before manifest verification; two named direct callers propagate… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) STAGE4_RAMROD.md:265
RAM-010 Zeroed saved-context loader populates named fields; no ordinary local write sets flag0x80… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) publication/README.md:1925
RAM-011 Prepare/resume register numeric context handles; apply/suspend require membership; suspend… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) publication/README.md:1925
RAM-012 Cleanup commands require Boolean-true helper entitlement; omitted reset-reserve flag defaults… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) publication/README.md:1935
RAM-013 Cleanup retains selected preflight/suspended/pending paths; false purge permits later removal;… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) publication/README.md:1956
RAM-014 Cleanup connection lifecycle and separate cleanup-target override traced; omitted UUID selects… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) publication/README.md:1978
RAM-015 Constructor validation failure frees outer context; snapshot-prepare failure skips new success… RAMDisk, ramrod, and brain bounded VERIFIED (bounded static or measured observation) publication/README.md:2002
USB-001 Proxy service definition references absent executable USB and launch services confirmed VERIFIED (bounded static or measured observation) REPORT.md:89
USB-002 Control socket lacks explicit loopback binding USB and launch services confirmed VERIFIED (bounded static or measured observation) REPORT.md:118
SIG-001 Supported executable pages match embedded CodeDirectories Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) REPORT.md:160
SIG-002 906 strict verification failures map to identical official source content Signatures, Image4, and trust confirmed VERIFIED (bounded static or measured observation) STAGE2_COMPARISON.md:79
SIG-003 868 standalone and one nested Image4 ticket signatures verify; 25 certificate signatures link… Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:27
SIG-004 All 69 PE EFI slices pass Apple-format signatures with a published public-key fingerprint Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:166
SIG-005 9702 signed object records satisfy examined certificate-role rules Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:52
SIG-006 Three supplied trust-cache encodings match signed ticket digests directly; four do not Signatures, Image4, and trust partial VERIFIED (partial scope); interpretation open STAGE3_FIRMWARE.md:66
SIG-007 Four alternate trust-cache files have official signed counterparts with identical entry arrays Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:88
SIG-008 All 2699 measured CodeDirectory records occur in the 15-cache official reference Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:9
SIG-009 Cleanup service code pages and populated special slots match; CMS integrity passes; blanket… Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) publication/README.md:2043
SIG-010 Fresh exact official BaseSystem and all five cleanup bundle files match; official image… Signatures, Image4, and trust bounded VERIFIED (bounded static or measured observation) publication/README.md:2021
FW-001 Three restore digest differences resolve by type-tag substitution Firmware, EFI, and NVRAM bounded VERIFIED (bounded static or measured observation) REPORT.md:126
FW-002 FTAB and DP855 declared digests reproduced from internal measured regions Firmware, EFI, and NVRAM confirmed VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:109
FW-003 All 36 UARP digest lists and 12 manifest board selections reproduced Firmware, EFI, and NVRAM confirmed VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:117
FW-004 Nine compressed PCI EFI payloads decode into bounded x86-64 PE drivers without certificate tables Firmware, EFI, and NVRAM confirmed VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:192
FW-005 Product.efi wrapper dispatch depends on runtime-variable decryption material Firmware, EFI, and NVRAM bounded VERIFIED (bounded static or measured observation) STAGE3_FIRMWARE.md:180
FW-006 PFX UARP and nested vendor configuration length-accounted with matching header/body CRCs Firmware, EFI, and NVRAM bounded VERIFIED (bounded static or measured observation) publication/README.md:1223
FW-007 All3PSFfirmware containers match reference and pass6CRCs; embedded RSA keys are distinct Firmware, EFI, and NVRAM bounded VERIFIED (bounded static or measured observation) publication/README.md:1269
FW-008 Apple-signed PSFFlasher uses PCI mailbox firmware download and boot-service-only status variables Firmware, EFI, and NVRAM bounded VERIFIED (bounded static or measured observation) publication/README.md:1269
FW-009 LoadedImage input and -p / efi-apple-payload* routes feed substring filename selection and… Firmware, EFI, and NVRAM confirmed static consumers; upstream authority unknown VERIFIED (bounded static or measured observation) publication/README.md:1314
FW-010 512-byte argv and path allocations,96-byte payload-pointer list, unchecked signed target index,… Firmware, EFI, and NVRAM confirmed local checks absent; exploitability unknown VERIFIED (bounded static or measured observation) publication/README.md:1341
FW-011 Security-query return ignored after buffer zeroing; unfilled zero response selects UnFused… Firmware, EFI, and NVRAM confirmed conditional control flow; no observed hardware event VERIFIED (bounded static or measured observation) publication/README.md:1314
FW-012 FirmwareUpdateLauncher consumes helper plists, assembles bless firmware/payload options and… Firmware, EFI, and NVRAM Confirmed bounded static workflow; exact PSF producer authority incomplete VERIFIED (bounded static or measured observation) derived table
FW-013 bless stages payloads and serializes EFI media paths/boot options for an IOKit NVRAM property… Firmware, EFI, and NVRAM Confirmed bounded static workflow VERIFIED (bounded static or measured observation) derived table
FW-014 MultiUpdater reads staged payloads, optionally requests IMG4 verification for seven types… Firmware, EFI, and NVRAM Confirmed caller behavior; protocol meaning corroborated by upstream definitions VERIFIED (bounded static or measured observation) derived table
FW-015 MultiUpdater child lookup returns zero when no payload matches; resume-state writer discards… Firmware, EFI, and NVRAM Confirmed static error-reporting gaps; runtime impact unverified VERIFIED (bounded static or measured observation) derived table
FW-016 Ordinary dictionary writes pass false permission override; current-task Boolean-true… Firmware, EFI, and NVRAM Observed static authorization checks VERIFIED (bounded static or measured observation) derived table
FW-017 XML array/dictionaries convert to binary EFI paths; successful conversion queues a -data… Firmware, EFI, and NVRAM Observed selected conversion and persistence-request chain VERIFIED (bounded static or measured observation) derived table
FW-018 Eight mappings cover seven helper names; eleven signed Mach-O helper paths and fifteen EFI… Firmware, EFI, and NVRAM Observed compiled mapping and scoped absence VERIFIED (bounded static or measured observation) derived table
FW-019 setProperty calls setMagicVariable but does not directly reject its subsequent… Firmware, EFI, and NVRAM Observed result-propagation gap; impact unknown VERIFIED (bounded static or measured observation) derived table
FW-020 Typed EFI path conversion and registry transport construction have bounded validation,… Firmware, EFI, and NVRAM bounded static analysis; runtime impact unresolved VERIFIED (bounded static or measured observation) derived table
FW-021 AppleEFINVRAM resync error-return path contains no matching unlock after acquiring the NVRAM mutex Firmware, EFI, and NVRAM bounded static analysis; reachability and impact unresolved VERIFIED (bounded static or measured observation) derived table
CFG-001 78465 selected plist candidates freshly hash-match inventory and parse across seven scopes Configuration and services bounded VERIFIED (bounded static or measured observation) STAGE5_CONFIGURATION.md:49
CFG-002 Seven Intel Python XML parser failures are accepted by Apple plutil and parse via native conversion Configuration and services resolved VERIFIED (bounded static or measured observation) STAGE5_CONFIGURATION.md:50
CFG-003 475 of 477 launch-directory plists declare programs; 439 resolve within same image and 36… Configuration and services bounded VERIFIED (bounded static or measured observation) STAGE5_CONFIGURATION.md:51
CFG-004 Stage5B reconciles 477 launch plist hash references and classifies 19 socket groups; 11 of 36… Configuration and services bounded VERIFIED (bounded static or measured observation) publication/README.md:347
SVC-001 Intel remoted CoreDevice handler checks caller audit-token entitlement presence; separate… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:355
SVC-002 Intel BaseSystem PAM module delegates to sshd-fvunlock through a pipe and checks helper… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:359
SVC-003 Identical USB mux sandbox profiles use active deny-default plus explicit grants; broad… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:365
SVC-004 Intel sshd-fvunlock checks AKS status and caller error state before APFS unlock loop;… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:371
SVC-005 Intel remoted local and remote service policy producers and override precedence traced with… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:389
SVC-006 Sixteen RemoteServices declarations and selected remoted exposure-policy branches reviewed;… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:395
SVC-007 Intel remoted checks required TLS before ordinary handshake completion and supplies a separate… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:417
SVC-008 Intel remoted conditionally verifies DCRT/DAK and compares attested public key with selected… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:429
SVC-009 Intel remoted DCRT helper accepts certain expiration failures through either expired-only check… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:446
SVC-010 Intel remoted base/controller/node required-OID methods include DCRT and DAK; node… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:456
SVC-011 Intel remoted outer chassis checks permit success on local-manifest-unavailable type16 or… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:469
SVC-012 Intel remoted chassis matching compares numeric identity pairs; parsers check hex scan success… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:484
SVC-013 RSDPreferences uses stored-domain current-user/current-host CFPreferences reads/writes and a… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:494
SVC-014 Intel remoted string preference then enabled feature then boot argument selects TLS policy… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:504
SVC-015 Compute TLS mutation is gated by audit-token entitlement object presence and maps Boolean… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:504
SVC-016 Identity startup schedules scoped stored-identity deletion separately from generation and… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:522
SVC-017 Intel remoted requests a 256-bit EC AppleKeyStore key and separately adds the resulting… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:534
SVC-018 Identity generation can omit DCRT DAK and chassis extensions while creation/storage failures… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:542
SVC-019 Async reload checks requested extension presence on stored identity but not after regeneration;… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:555
SVC-020 Local get_local_device_identity serializes token object blob and certificate; no entitlement or… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:565
SVC-021 Identity completions differ; compute helper selects TLS-disable configuration on null identity… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:578
SVC-022 Global populated-OID metadata is included in outgoing handshake Properties and peer parser… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:565
SVC-023 authenticate_device parses supplied certificate and returns a checked type/OID evaluator… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:600
SVC-024 Exact-cache framework reconstructs local identity through AppleKeyStore token-OID attributes… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:610
SVC-025 RSD certificate-query reply callback accepts null result-string return and feeds a TLS… Remote services, TLS, and identity requires investigation VERIFIED observation; impact UNKNOWN publication/README.md:654
SVC-026 AppleKeyStore request selects SEP token/session classes; local key implementation selected… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:679
SVC-027 Concrete SEP key constructors distinguish unknown identifiers from denied system keys;… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:709
SVC-028 Deferred token object is reconstructed before operation; registered-token errors permit one… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:742
SVC-029 CTKD passes the current XPC connection to a new local key; shared key-cache hits compare object… Remote services, TLS, and identity bounded; requires investigation VERIFIED (bounded static or measured observation) publication/README.md:769
SVC-030 AKS setter removes prior parameter before replacement validation; import/signing wrappers check… Remote services, TLS, and identity bounded VERIFIED (bounded static or measured observation) publication/README.md:791
NET-001 Seven-scope lexical network-reference census accounts for105123 paths;104514 hash-matched… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:810
NET-002 Restore-library URL defaults, override setters and FDR trust-object GET selection traced in… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:850
NET-003 Typed EnableSslValidation=false constructs an AMSupport disable-validation option; additional… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:896
NET-004 Selected Memory-to-Remote recovery path checks trust-object SHA256 against rfta/DGST; separate… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:918
NET-005 FDR HTTP callback signs and retries401/419 client challenges; trust-root extraction parses DER;… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:981
NET-006 AP-ticket trust helper has a typed AllowUntrusted true-return path; digest-mismatch exception… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:961
NET-007 FDR ticket helper reaches selected Image4 chain/signature/property gates with verified policy… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1005
NET-008 Ticket population checks trust after assigning loaded APTicket; input providers and four direct… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1052
NET-009 FDR validation-disable option reaches AMS session delegate UseCredential; constructor, request… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1088
NET-010 Custom-root helper tests certificate index0 using DER equality or direct issuer RSA… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1123
NET-011 Transport RSA helper differs from Image4 helper: legacy false Boolean can return success; newer… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1131
NET-012 PFX selects local signing and skips generic response parsing; shared TSS callback copies… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1154
NET-013 PFX opens ApplePM40100MgmtEP user client and queries selector2; named send function delivers to… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1154
NET-014 PFX device submission occurs during staging via IOKit selector4; later apply callback sets… Restore network and FDR bounded VERIFIED (bounded static or measured observation) publication/README.md:1223