Firmware, EFI, and NVRAM findings
Home · Findings index · Subsystem analysis
The source crosswalk maps every ID to a retained audit document and distinguishes an explicit ID mention from section context. Each record retains the original audit ledger wording and its explicit limit. Raw disassembly, copies of Apple binaries, and host-specific artifacts are intentionally absent. A bounded finding describes only the examined path or artifact.
FW-001 — Three restore digest differences resolve by type-tag substitution
Status: bounded
Retained source: REPORT.md:126 (relevant source section; ID absent from narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-catalog
Evidence: Restore firmware comparison
Observation: Three restore digest differences resolve by type-tag substitution
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: Device-side enforcement and full firmware analysis remain incomplete
Follow-up: Device-side enforcement and full firmware analysis remain incomplete
FW-002 — FTAB and DP855 declared digests reproduced from internal measured regions
Status: confirmed
Retained source: STAGE3_FIRMWARE.md:109 (relevant source section; ID absent from narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-catalog
Evidence: Stage 3 firmware report and digest reconstruction records
Observation: FTAB and DP855 declared digests reproduced from internal measured regions
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: DP855 region layout inferred for this artifact; device verifier not traced
Follow-up: DP855 region layout inferred for this artifact; device verifier not traced
FW-003 — All 36 UARP digest lists and 12 manifest board selections reproduced
Status: confirmed
Retained source: STAGE3_FIRMWARE.md:117 (relevant source section; ID absent from narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-catalog
Evidence: 126 revision-rule measurements and board selection ledger
Observation: All 36 UARP digest lists and 12 manifest board selections reproduced
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: No controller session or installed revision observed
Follow-up: No controller session or installed revision observed
FW-004 — Nine compressed PCI EFI payloads decode into bounded x86-64 PE drivers without certificate tables
Status: confirmed
Retained source: STAGE3_FIRMWARE.md:192 (relevant source section; ID absent from narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-catalog
Evidence: Decompression size/hash/PE checks and saved disassembly
Observation: Nine compressed PCI EFI payloads decode into bounded x86-64 PE drivers without certificate tables
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: Outer ROM authentication and historical loading are separate
Follow-up: Outer ROM authentication and historical loading are separate
FW-005 — Product.efi wrapper dispatch depends on runtime-variable decryption material
Status: bounded
Retained source: STAGE3_FIRMWARE.md:180 (relevant source section; ID absent from narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-catalog
Evidence: Static diagnostic loader trace and wrapper length fields
Observation: Product.efi wrapper dispatch depends on runtime-variable decryption material
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: No runtime material collected; plaintext and trailer remain unverified
Follow-up: No runtime material collected; plaintext and trailer remain unverified
FW-006 — PFX UARP and nested vendor configuration length-accounted with matching header/body CRCs
Status: bounded
Retained source: publication/README.md:1223 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-personalization
Evidence: All outer/nested byte regions; pinned vendor CRC; archive/TLV decoding; encoding checks
Observation: PFX UARP and nested vendor configuration length-accounted with matching header/body CRCs
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: Signed message and device trust anchor unverified; register semantics incomplete
Follow-up: Signed message and device trust anchor unverified; register semantics incomplete
FW-007 — All3PSFfirmware containers match reference and pass6CRCs; embedded RSA keys are distinct
Status: bounded
Retained source: publication/README.md:1269 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F3 acquired hashes; prior exact-reference linkage; bounded vendor layout and encoding
Observation: All3PSFfirmware containers match reference and pass6CRCs; embedded RSA keys are distinct
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: PSS encoding is not signature verification; inner code and device key policy unresolved
Follow-up: PSS encoding is not signature verification; inner code and device key policy unresolved
FW-008 — Apple-signed PSFFlasher uses PCI mailbox firmware download and boot-service-only status variables
Status: bounded
Retained source: publication/README.md:1269 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: 15byte-checked ranges1841records; original PCI GUID; vendor MRPC and UEFI ABI; prior exact-hash EFI signature
Observation: Apple-signed PSFFlasher uses PCI mailbox firmware download and boot-service-only status variables
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: No execution established;launch/argument authority, malformed-input and individual I/O error handling incomplete
Follow-up: No execution established;launch/argument authority, malformed-input and individual I/O error handling incomplete
FW-009 — LoadedImage input and -p / efi-apple-payload* routes feed substring filename selection and conditional filename-version/force gate
Status: confirmed static consumers; upstream authority unknown
Retained source: publication/README.md:1314 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F4 inputs.original-byte trace and Stage6F3 main/download/PCI trace; RVAs 0x8ef9,0x9550,0xbc81,0xbcdb,0xa314
Observation: LoadedImage input and -p / efi-apple-payload* routes feed substring filename selection and conditional filename-version/force gate
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: No authenticated external producer identified; no observed launch or rollback bypass
Follow-up: No authenticated external producer identified; no observed launch or rollback bypass
FW-010 — 512-byte argv and path allocations,96-byte payload-pointer list, unchecked signed target index, uninitialized initial EFI variable DataSize, header arithmetic before bounds, individual PCI errors discarded
Status: confirmed local checks absent; exploitability unknown
Retained source: publication/README.md:1341 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F4 inputs.original-byte trace and Stage6F3 main/download/PCI trace; RVAs 0x8fdc,0x9b41,0x965b,0x966b,0x96a6,0x9748,0x982d,0xb69c,0xb6ca,0xac16,0xad1c,0xad9f
Observation: 512-byte argv and path allocations,96-byte payload-pointer list, unchecked signed target index, uninitialized initial EFI variable DataSize, header arithmetic before bounds, individual PCI errors discarded
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: Three valid packaged files pass all6CRCs; caller input control, runtime effects and transport-error reachability unproven
Follow-up: Three valid packaged files pass all6CRCs; caller input control, runtime effects and transport-error reachability unproven
FW-011 — Security-query return ignored after buffer zeroing; unfilled zero response selects UnFused success and dev_signed host filename label
Status: confirmed conditional control flow; no observed hardware event
Retained source: publication/README.md:1314 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F4 inputs.original-byte trace and Stage6F3 main/download/PCI trace; RVAs 0xbf56,0xbf6e,0xbf79,0xbf7e,0xc107,0xc10c,0xc139,0x10fd0
Observation: Security-query return ignored after buffer zeroing; unfilled zero response selects UnFused success and dev_signed host filename label
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: Does not alter fuses or enforce/bypass device authentication; packaged PSF names areprod_signed; no malformed inputs executed
Follow-up: Does not alter fuses or enforce/bypass device authentication; packaged PSF names areprod_signed; no malformed inputs executed
FW-012 — FirmwareUpdateLauncher consumes helper plists, assembles bless firmware/payload options and efi-apple-payload index names, requests NVRAM changes; compiled status table associates PSFFlasher with psfupdater
Status: Confirmed bounded static workflow; exact PSF producer authority incomplete
Retained source: publication/README.md:1374 (explicit ID in source narrative)
Related public data: tables/firmware-helpers.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F5 launcher10ranges2361records179metadata checks; fresh exact-image acquisition and strict signing; path census
Observation: FirmwareUpdateLauncher consumes helper plists, assembles bless firmware/payload options and efi-apple-payload index names, requests NVRAM changes; compiled status table associates PSFFlasher with psfupdater
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: No inventoried psfupdater path; a USB-C helper corroborates the generic schema, while initiating caller/helper authority, effective kernel/firmware policy and PSF-specific handoff remain unknown; no execution or writes performed
Follow-up: Locate an authoritative same-build psfupdater or alternate producer; trace launcher acceptance and device-side trust without running an updater on the production host
FW-013 — bless stages payloads and serializes EFI media paths/boot options for an IOKit NVRAM property request; signed private installer/boot/snapshot/NVRAM entitlements present
Status: Confirmed bounded static workflow
Retained source: publication/README.md:1408 (explicit ID in source narrative)
Related public data: tables/firmware-helpers.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F6 fresh reference-linked bless;6ranges1915records10metadata139import checks
Observation: bless stages payloads and serializes EFI media paths/boot options for an IOKit NVRAM property request; signed private installer/boot/snapshot/NVRAM entitlements present
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: Kernel conversion to -data variables and authorization not traced; entitlement presence does not prove execution or root caller
Follow-up: Kernel conversion to -data variables and authorization not traced; entitlement presence does not prove execution or root caller
FW-014 — MultiUpdater reads staged payloads, optionally requests IMG4 verification for seven types including psfu, supplies true verification callback to Apple loader, sets child LoadOptions and calls StartImage; update state uses attributes7
Status: Confirmed caller behavior; protocol meaning corroborated by upstream definitions
Retained source: publication/README.md:1431 (explicit ID in source narrative)
Related public data: tables/firmware-helpers.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F6 21ranges1401original-byte records; pinned AppleLoadImage/AppleSecureBoot headers and UEFI ABI; prior exact reference/signature links
Observation: MultiUpdater reads staged payloads, optionally requests IMG4 verification for seven types including psfu, supplies true verification callback to Apple loader, sets child LoadOptions and calls StartImage; update state uses attributes7
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: Protocol definitions are external research, not OpenCore evidence; actual Apple firmware loader/device acceptance and active policy unknown
Follow-up: Protocol definitions are external research, not OpenCore evidence; actual Apple firmware loader/device acceptance and active policy unknown
FW-015 — MultiUpdater child lookup returns zero when no payload matches; resume-state writer discards SetVariable return; selected caller ignores result-writer status
Status: Confirmed static error-reporting gaps; runtime impact unverified
Retained source: publication/README.md:1408 (explicit ID in source narrative)
Related public data: tables/firmware-helpers.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: firmware-flashers
Evidence: Stage6F6 checked d3d5-d440, d578-d63e and main db45/db48
Observation: MultiUpdater child lookup returns zero when no payload matches; resume-state writer discards SetVariable return; selected caller ignores result-writer status
Interpretation: Prior scoped conclusion retained; see status and limit
Security relevance: See linked finding context; not independently re-rated in this segment
Confidence field: Unknown in this new field; prior status/evidence classification preserved
Limit: No malformed input or failure injected; no proof of successful flash, exploitability or boot-policy bypass; trusted producer constraints unresolved
Follow-up: No malformed input or failure injected; no proof of successful flash, exploitability or boot-policy bypass; trusted producer constraints unresolved
FW-016 — Ordinary dictionary writes pass false permission override; current-task Boolean-true entitlement checks, legacy/name rules and separate LocalPolicy-storage entitlement
Status: Observed static authorization checks
Retained source: publication/README.md:1463 (explicit ID in source narrative)
Related public data: tables/efi-converter-branches.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: nvram-efi-paths
Evidence: Stage6F7 nvram.instructions, entitlement-table, legacy-table and rebase-corroboration; 196403a/196403c,196358d,19635bd
Observation: Selected caller passes false; checker compares entitlement object with kOSBooleanTrue; LocalPolicy storage additionally requires com.apple.private.security.bootpolicy.nvram
Interpretation: Firmware-payload ordinary write route is gated; generic root privilege does not replace the GUID-specific entitlement
Security relevance: Kernel NVRAM mutation boundary
Confidence field: Observed
Limit: MAC/sandbox/AMFI/entry checks and all override callers remain open; no runtime policy test
Follow-up: Trace registry/MAC entry path and every true override caller
FW-017 — XML array/dictionaries convert to binary EFI paths; successful conversion queues a -data companion; sync reaches a static indirect EFI runtime call with attributes7
Status: Observed selected conversion and persistence-request chain
Retained source: publication/README.md:1497 (explicit ID in source narrative)
Related public data: tables/efi-converter-branches.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: nvram-efi-paths
Evidence: Stage6F7 provider.instructions, pointer-links, nvram.instructions; 14865d1,1486602,196317b,1963263,196066f,19628b0
Observation: OSUnserializeXML, typed casts, UTF16 media-path/option construction, -data suffix and pending dictionary-to-setVariable calls retained
Interpretation: Companion data is an EFI path representation and queued modification, not firmware bytes or proof of persistence
Security relevance: Pre-boot payload selection and kernel-to-firmware handoff
Confidence field: Observed
Limit: No actual write observed; full input validation, MAC/entry authority and firmware acceptance unresolved
Follow-up: Complete converter size/error/ownership branches and registry/MAC entry controls; firmware implementation needs additional artifact
FW-018 — Eight mappings cover seven helper names; eleven signed Mach-O helper paths and fifteen EFI flasher paths; psfupdater basename absent in enumerated trees
Status: Observed compiled mapping and scoped absence
Retained source: publication/README.md:1650 (explicit ID in source narrative)
Related public data: tables/efi-converter-branches.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: nvram-efi-paths
Evidence: Stage6F7 launcher-authority constant/instruction proof, helper-census; publication/FIRMWARE_HELPERS.csv
Observation: Fixed updater-name predicate and all eight dictionaries decoded; census joins hashes and retained signing records
Interpretation: Architecture variants and repeated/alternate payload locations explain multiplicity; missing helper remains provenance question
Security relevance: Helper selection and privileged producer inputs
Confidence field: Observed
Limit: No historical helper binary established; helper-internal authorization/platform restrictions not traced; absence not exhaustive across opaque containers
Follow-up: Reverse engineer located helpers and trace caller/directory authority; inspect package manifests for psfupdater
FW-019 — setProperty calls setMagicVariable but does not directly reject its subsequent original-variable queueing on a false conversion result
Status: Observed result-propagation gap; impact unknown
Retained source: publication/README.md:1519 (explicit ID in source narrative)
Related public data: tables/efi-converter-branches.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: nvram-efi-paths
Evidence: Stage6F7 nvram.instructions/annotated; 1963625 through19637ea
Observation: Return used for optional logging, no result-dependent rejection before original-variable cache/pending processing
Interpretation: Conversion and original-property acceptance have separate outcomes; conversion failure may not surface as property failure
Security relevance: Error reporting and possible stale/partial state across a firmware staging boundary
Confidence field: Observed
Limit: Not a demonstrated vulnerability or successful persistent write; stale companion behavior and reachable failure inputs need further work
Follow-up: Trace all companion consumers/deletion and synchronization results; define a safe isolated model before any runtime experiment
FW-020 — Typed EFI path conversion and registry transport construction have bounded validation, append-result, media-read-error and metadata-ownership limitations
Status: bounded static analysis; runtime impact unresolved
Retained source: publication/README.md:1527 (explicit ID in source narrative)
Related public data: tables/efi-converter-branches.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: nvram-efi-paths
Evidence: Stage6F7 provider.instructions; continuation converter-new.*, converter-types, converter-branch-review and arithmetic-examples; EFI_CONVERTER_BRANCHES.csv; stage6f7-transport-20260927 transport.provenance.json, transport-review.json and iomedia-slot-links.json; 1820 checked instructions/11 helpers
Observation: 22typed branches reviewed; four-field MAC parser;16bit file/node arithmetic; common append failures ignored while CDROM checks; retained metadata lacks release on selected replacement/error/null-output paths; eleven selected transport append results unused; MBR read error can return success without setting the zero-initialized signature output
Interpretation: Potential malformed or incomplete path generation and reference-leak candidates; OSData itself rejects length overflow and inadequate capacity; MBR zero-signature node is a static error-propagation candidate, not an observed boot failure
Security relevance: Privileged boot-path parsing and error/ownership boundary before NVRAM staging
Confidence field: Observed branch behavior; arithmetic/lifetime effects Supported inference; runtime impact Unknown
Limit: No runtime malformed input or allocation/read failure induced; firmware acceptance, boot impact, overflow exploitation and security bypass unproven
Follow-up: Trace authorized caller/property producers, append/read failure reachability, downstream EFI-path consumers and firmware acceptance in an isolated model
FW-021 — AppleEFINVRAM resync error-return path contains no matching unlock after acquiring the NVRAM mutex
Status: bounded static analysis; reachability and impact unresolved
Retained source: publication/README.md:1463 (explicit ID in source narrative)
Related public data: tables/efi-converter-branches.csv
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: nvram-efi-paths
Evidence: resyncAllVariables196420e..42c8; lock4228; firmware call4240; error4247->429d->4290/4297; success unlock4288; continuation validation.json15recordCFG; stage6f7-policy-20260927 exact equality/sandboxcallback/pointer proofs
Observation: Nonzero ResyncNVRam deletion result follows optional logging to return without the local unlock; successful route flushes/caches/unlocks
Interpretation: Potential retained-lock error-handling defect in official-matching binary; not evidence of modification or unauthorized firmware access
Security relevance: Possible availability impact at privileged NVRAM synchronization boundary if the error route is reachable
Confidence field: Observed local control flow; retained-lock consequence Supported inference; reachability/impact Unknown
Limit: No resync request or firmware-error induction; equality and concrete sandboxcallback traced, but evaluator/profile/caller and firmware-error reachability unresolved; no demonstrated deadlock or denial of service
Follow-up: Resolve sb_evaluate_internal3033f55, effectiveprofile/globalpolicy, remainingMACregistration/kernelcallers and firmwareerrors before isolated dynamicvalidation