Skip to the content.

Remote services, TLS, and identity findings

Home · Findings index · Subsystem analysis

The source crosswalk maps every ID to a retained audit document and distinguishes an explicit ID mention from section context. Each record retains the original audit ledger wording and its explicit limit. Raw disassembly, copies of Apple binaries, and host-specific artifacts are intentionally absent. A bounded finding describes only the examined path or artifact.

SVC-001 — Intel remoted CoreDevice handler checks caller audit-token entitlement presence; separate device-admin helper controls sensitive-property descriptions

Status: bounded
Retained source: publication/README.md:355 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5C remoted listener block0x100063040; token lookup0x100003dae; missing-object branch0x100003dc6; helper0x10002c9b8 and selector0x10002b924

Observation: Intel remoted CoreDevice handler checks caller audit-token entitlement presence; separate device-admin helper controls sensitive-property descriptions

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Presence check differs from Boolean-true check; not complete command authorization or network-peer authentication; no unauthorized route established

Follow-up: Presence check differs from Boolean-true check; not complete command authorization or network-peer authentication; no unauthorized route established

SVC-002 — Intel BaseSystem PAM module delegates to sshd-fvunlock through a pipe and checks helper failures before success reboot transition

Status: bounded
Retained source: publication/README.md:359 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5C matched PAM module; spawn0x87c; pipe write0x8d1; wait0x8f7; exit classification0x973; reboot3 call0xa29; version-bounded Apple FileVault documentation

Observation: Intel BaseSystem PAM module delegates to sshd-fvunlock through a pipe and checks helper failures before success reboot transition

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Stage5D extends helper AKS/APFS tracing; backend throttling full target/input mapping and PAM module resolution remain open; Remote Login enabled state and historical unlocking unmeasured

Follow-up: Stage5D extends helper AKS/APFS tracing; backend throttling full target/input mapping and PAM module resolution remain open; Remote Login enabled state and historical unlocking unmeasured

SVC-003 — Identical USB mux sandbox profiles use active deny-default plus explicit grants; broad allow-default examples are comments

Status: bounded
Retained source: publication/README.md:365 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5C both profile hashes04dce17fc70baebcc38bbec7711208986808baa2f2621c29262d67f1e937aab9; retained profile text

Observation: Identical USB mux sandbox profiles use active deny-default plus explicit grants; broad allow-default examples are comments

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Imported policy composition and actual consumer untraced; capabilities do not prove execution pairing or network traffic

Follow-up: Imported policy composition and actual consumer untraced; capabilities do not prove execution pairing or network traffic

SVC-004 — Intel sshd-fvunlock checks AKS status and caller error state before APFS unlock loop; subsequent ACM callback logs policy result without constructing an authentication error

Status: bounded
Retained source: publication/README.md:371 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5D inventory-matched helper f3632d5a884f458c2f8446f498f4f9f004eac5a6ad8b0e5bb301359c0e76b99e; AKS gate0x100007435; caller0x1000039be; APFS0x1000045fa; callback0x100004aa0; function-start and LLDB entry checks

Observation: Intel sshd-fvunlock checks AKS status and caller error state before APFS unlock loop; subsequent ACM callback logs policy result without constructing an authentication error

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Not a bypass finding; backend verifier throttling full target/input mapping ARM equivalence and runtime unlocking remain unverified; public source version differs

Follow-up: Not a bypass finding; backend verifier throttling full target/input mapping ARM equivalence and runtime unlocking remain unverified; public source version differs

SVC-005 — Intel remoted local and remote service policy producers and override precedence traced with three access-helper callers

Status: bounded
Retained source: publication/README.md:389 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5E local init0x100005494; description writer0x100005cf7; remote constructor0x10000c956; gate0x100029d88; callers0x10000c600 0x10002cc0c 0x10002d2a7

Observation: Intel remoted local and remote service policy producers and override precedence traced with three access-helper callers

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Remote description provenance and transport identity unresolved; entitlement presence is not Boolean true; no unauthorized override or complete connection authorization established

Follow-up: Remote description provenance and transport identity unresolved; entitlement presence is not Boolean true; no unauthorized override or complete connection authorization established

SVC-006 — Sixteen RemoteServices declarations and selected remoted exposure-policy branches reviewed; missing EncryptSocketData defaults false in local description

Status: bounded
Retained source: publication/README.md:395 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5E 14 hash-linked plist paths; setExposePolicy0x100005ee0; selected serviceWantsToBeExposedToDevice branches; default writer0x100005e37

Observation: Sixteen RemoteServices declarations and selected remoted exposure-policy branches reviewed; missing EncryptSocketData defaults false in local description

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Exposure flags do not establish activation or unauthenticated access; per-service encryption property does not prove outer transport plaintext; ARM control flow and full policy composition untraced

Follow-up: Exposure flags do not establish activation or unauthenticated access; per-service encryption property does not prove outer transport plaintext; ARM control flow and full policy composition untraced

SVC-007 — Intel remoted checks required TLS before ordinary handshake completion and supplies a separate Boolean verification callback to RemoteXPC

Status: bounded
Retained source: publication/README.md:417 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5F policy mapper0x10001c7a4; negotiation0x100007b9f; required check0x100007f37; cancel0x100008097; set_tls0x100008458; callback0x100008bc8; authentication helper0x10001f9dc

Observation: Intel remoted checks required TLS before ordinary handshake completion and supplies a separate Boolean verification callback to RemoteXPC

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Enable flag is negotiation intent not crypto success; certificate evaluator identity provenance backend policy RemoteXPC enforcement and accepted-description integrity unresolved; no runtime authentication measured

Follow-up: Enable flag is negotiation intent not crypto success; certificate evaluator identity provenance backend policy RemoteXPC enforcement and accepted-description integrity unresolved; no runtime authentication measured

SVC-008 — Intel remoted conditionally verifies DCRT/DAK and compares attested public key with selected peer certificate; two embedded roots match Apple public constants

Status: bounded
Retained source: publication/README.md:429 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5G evaluator0x10001fec9; trust helper0x1000230de; AKS verify0x100021130; equality0x100021264; two extracted root self-signatures and DER hash matches

Observation: Intel remoted conditionally verifies DCRT/DAK and compares attested public key with selected peer certificate; two embedded roots match Apple public constants

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Required OID set and device type determine paths; chassis and AKS internals remain incomplete; public Security source not exact-build verification; no peer authentication tested

Follow-up: Required OID set and device type determine paths; chassis and AKS internals remain incomplete; public Security source not exact-build verification; no peer authentication tested

SVC-009 — Intel remoted DCRT helper accepts certain expiration failures through either expired-only check or error domain/code match

Status: requires investigation
Retained source: publication/README.md:446 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5G SecTrustEvaluateWithError0x1000238db; SecTrustIsExpiredOnly0x1000238ec; NSOSStatusErrorDomain/-67818 match0x10002390a; null-error success0x100023ba5

Observation: Intel remoted DCRT helper accepts certain expiration failures through either expired-only check or error domain/code match

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Domain/code fallback does not itself inspect all trust failures; exact-build aggregation and effective peer policy unresolved; no arbitrary certificate acceptance or exploitable bypass demonstrated

Follow-up: Domain/code fallback does not itself inspect all trust failures; exact-build aggregation and effective peer policy unresolved; no arbitrary certificate acceptance or exploitable bypass demonstrated

SVC-010 — Intel remoted base/controller/node required-OID methods include DCRT and DAK; node conditionally adds chassis OID; ordinary chassis policy precedence and false default traced

Status: bounded
Retained source: publication/README.md:456 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5H three constant arrays; four class methods; verification caller0x10001fa38; chassis helper0x10001a4e8; setting resolver0x10001c7ff

Observation: Intel remoted base/controller/node required-OID methods include DCRT and DAK; node conditionally adds chassis OID; ordinary chassis policy precedence and false default traced

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Loopback returns empty; TLS activation and all class inheritance not established; preferences implementation and effective settings unresolved

Follow-up: Loopback returns empty; TLS activation and all class inheritance not established; preferences implementation and effective settings unresolved

SVC-011 — Intel remoted outer chassis checks permit success on local-manifest-unavailable type16 or absent optional peer manifest type15

Status: requires investigation
Retained source: publication/README.md:469 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5H null local manifest0x1000217b6 to success0x100021f3e; peer absence0x100021988 and policy0x1000220e0; optional success0x100022c43; present-invalid and matcher-result failure routes

Observation: Intel remoted outer chassis checks permit success on local-manifest-unavailable type16 or absent optional peer manifest type15

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Earlier DCRT/DAK requirements remain; inner matchers AMFDR and settings protections incomplete; no hostile input control or unauthorized peer access demonstrated

Follow-up: Earlier DCRT/DAK requirements remain; inner matchers AMFDR and settings protections incomplete; no hostile input control or unauthorized peer access demonstrated

SVC-012 — Intel remoted chassis matching compares numeric identity pairs; parsers check hex scan success without explicit full-field consumption and local identity conversions have unchecked results

Status: requires investigation
Retained source: publication/README.md:484 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5I parsers0x100023c55/0x100025206; node comparisons0x1000248aa/0x1000248ba; controller equality0x100025042; CFNumberGetValue0x100024c41/0x100024c51; separate seven-case host Scanner probe

Observation: Intel remoted chassis matching compares numeric identity pairs; parsers check hex scan success without explicit full-field consumption and local identity conversions have unchecked results

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Host25G229 differs from audited25G83; input authenticity and provider guarantees unresolved; no target execution or forged identity acceptance demonstrated

Follow-up: Host25G229 differs from audited25G83; input authenticity and provider guarantees unresolved; no target execution or forged identity acceptance demonstrated

SVC-013 — RSDPreferences uses stored-domain current-user/current-host CFPreferences reads/writes and a bounded version-marker migration

Status: bounded
Retained source: publication/README.md:494 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5I getter0x100011133; setter0x1000111c3; migration0x100010f9b; embedded integers0/1; synchronize0x100011212; six direct setter-selector references

Observation: RSDPreferences uses stored-domain current-user/current-host CFPreferences reads/writes and a bounded version-marker migration

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: No backing-file path ACL effective runtime user persistence success or caller write authorization established; no live preferences read or changed

Follow-up: No backing-file path ACL effective runtime user persistence success or caller write authorization established; no live preferences read or changed

SVC-014 — Intel remoted string preference then enabled feature then boot argument selects TLS policy before backend defaults

Status: bounded
Retained source: publication/README.md:504 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5J resolver0x10001ce4b; compute0x1000323c5; NCM0x100037805; loopback0x100039d24; five-entry hardware dictionary0x1000658c0

Observation: Intel remoted string preference then enabled feature then boot argument selects TLS policy before backend defaults

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Defaults differ by backend; no actual MobileGestalt preferences boot arguments or traffic acquired; disabled policy does not prove plaintext or a vulnerability

Follow-up: Defaults differ by backend; no actual MobileGestalt preferences boot arguments or traffic acquired; disabled policy does not prove plaintext or a vulnerability

SVC-015 — Compute TLS mutation is gated by audit-token entitlement object presence and maps Boolean false/true to optional/required

Status: requires investigation
Retained source: publication/README.md:504 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5J entitlement lookup0x10001bd71 presence check0x10001bd82; require_tls handler0x10001c638 and setter0x100032359

Observation: Compute TLS mutation is gated by audit-token entitlement object presence and maps Boolean false/true to optional/required

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: No explicit entitlement Boolean-truth test on reviewed path; issuance external writers persistence and runtime reachability unresolved; no unprivileged mutation demonstrated

Follow-up: No explicit entitlement Boolean-truth test on reviewed path; issuance external writers persistence and runtime reachability unresolved; no unprivileged mutation demonstrated

SVC-016 — Identity startup schedules scoped stored-identity deletion separately from generation and replacement of the TLS prerequisite slot

Status: bounded
Retained source: publication/README.md:522 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5J startup0x10001f335 block0x10001f41f deletion0x10001e87d replacement0x10001d32e; generation wrapper0x10001d301 and administrative entitlement lookup0x10002ee96

Observation: Identity startup schedules scoped stored-identity deletion separately from generation and replacement of the TLS prerequisite slot

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Stage5K expands ordinary generator and reload behavior; complete caller framework and metadata-publication enforcement remain partial; no live keychain identity or private key acquired

Follow-up: Stage5K expands ordinary generator and reload behavior; complete caller framework and metadata-publication enforcement remain partial; no live keychain identity or private key acquired

SVC-017 — Intel remoted requests a 256-bit EC AppleKeyStore key and separately adds the resulting identity to the system keychain

Status: bounded
Retained source: publication/README.md:534 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5K ACL0x10001d615 flags0x40000000; key0x10001d73a; integer256 at0x100065890; identity-add0x10001dfb9; pinned Apple headers

Observation: Intel remoted requests a 256-bit EC AppleKeyStore key and separately adds the resulting identity to the system keychain

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Token name does not prove Secure Enclave residency; public header permits kernel emulation; no actual key storage or hardware state acquired

Follow-up: Token name does not prove Secure Enclave residency; public header permits kernel emulation; no actual key storage or hardware state acquired

SVC-018 — Identity generation can omit DCRT DAK and chassis extensions while creation/storage failures return null

Status: bounded
Retained source: publication/README.md:542 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5K missing-material branches0x10001d796/0x10001dcc7/0x10001dd7f; self-sign0x10001dead; failure cleanup0x10001e3d5 and return0x10001e586

Observation: Identity generation can omit DCRT DAK and chassis extensions while creation/storage failures return null

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Producer success is separate from peer verification; required OIDs remain enforced on earlier examined class paths; exact backend and exception behavior unresolved

Follow-up: Producer success is separate from peer verification; required OIDs remain enforced on earlier examined class paths; exact backend and exception behavior unresolved

SVC-019 — Async reload checks requested extension presence on stored identity but not after regeneration; null-slot refresh leaves OID metadata unchanged

Status: requires investigation
Retained source: publication/README.md:555 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5K containment0x10001f13e; regenerate0x10001f206 to replacement dispatch0x10001f284; refresh0x10000d064/0x10000d08a

Observation: Async reload checks requested extension presence on stored identity but not after regeneration; null-slot refresh leaves OID metadata unchanged

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Caller completion other writers publication timing and peer enforcement unresolved; no stale wire advertisement or authentication bypass demonstrated

Follow-up: Caller completion other writers publication timing and peer enforcement unresolved; no stale wire advertisement or authentication bypass demonstrated

SVC-020 — Local get_local_device_identity serializes token object blob and certificate; no entitlement or UID gate in inspected listener/getter route

Status: requires investigation
Retained source: publication/README.md:565 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5L Mach listener0x10002bed9; dispatcher0x10002c04b; async caller0x10002ec1b; completion0x10002f3ed; token attribute0x10002f622; reply0x10002ed27

Observation: Local get_local_device_identity serializes token object blob and certificate; no entitlement or UID gate in inspected listener/getter route

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: External Mach/sandbox reachability and token-use rights unresolved; no plaintext key disclosure or actual request demonstrated; query can reach generation

Follow-up: External Mach/sandbox reachability and token-use rights unresolved; no plaintext key disclosure or actual request demonstrated; query can reach generation

SVC-021 — Identity completions differ; compute helper selects TLS-disable configuration on null identity while TLS-enabled loopback crashes

Status: requires investigation
Retained source: publication/README.md:578 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5L six direct callers; arrays657b8/657e8; compute helper0x100032e1e; nw_parameters_create_secure_tcp0x100017748; loopback0x100039408 to0x10004cee7

Observation: Identity completions differ; compute helper selects TLS-disable configuration on null identity while TLS-enabled loopback crashes

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Layer-specific configuration not established accepted plaintext transport; downstream RemoteXPC setup and enforcement incomplete; no identity or connection experiment

Follow-up: Layer-specific configuration not established accepted plaintext transport; downstream RemoteXPC setup and enforcement incomplete; no identity or connection experiment

SVC-022 — Global populated-OID metadata is included in outgoing handshake Properties and peer parser collects string elements

Status: bounded
Retained source: publication/README.md:565 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5L global0x10006e370; property attachment0x100008600; send0x100008ad9; tlsOidsPopulatedOnPeer0x10000791e

Observation: Global populated-OID metadata is included in outgoing handshake Properties and peer parser collects string elements

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Other writers and timing incomplete; no stale wire metadata or peer acceptance established; advertisement not certificate authentication

Follow-up: Other writers and timing incomplete; no stale wire metadata or peer acceptance established; advertisement not certificate authentication

SVC-023 — authenticate_device parses supplied certificate and returns a checked type/OID evaluator result; it is distinct from private-key possession or live TLS authentication

Status: bounded
Retained source: publication/README.md:600 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5M dispatcher0x10002adb6; call0x10002b49f; identity_cert read0x10002e0ab; parse0x10002e0c2; evaluator0x100023033; OK0x10002e15d

Observation: authenticate_device parses supplied certificate and returns a checked type/OID evaluator result; it is distinct from private-key possession or live TLS authentication

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Endpoint distribution and complete authorization unresolved; earlier evaluator exceptions remain; no actual certificate or peer submitted; does not consume identity_key

Follow-up: Endpoint distribution and complete authorization unresolved; earlier evaluator exceptions remain; no actual certificate or peer submitted; does not consume identity_key

SVC-024 — Exact-cache framework reconstructs local identity through AppleKeyStore token-OID attributes and adapts it to a TLS identity

Status: requires investigation
Retained source: publication/README.md:610 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: 132 exports agree with original nlist; client request and checked parsing; 33 slide-pointer checks and 13 import-stub corroborations; SecKeyCreateWithData and SecIdentityCreate argument trace; Stage5O Security token dispatch session construction object lookup and registered-token exception

Observation: Exact-cache framework reconstructs local identity through AppleKeyStore token-OID attributes and adapts it to a TLS identity

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: No real token obtained or used; endpoint reachability and provider authorization unresolved; no plaintext private-key disclosure or accepted TLS session established; nonnull wrapper is not proof of usable token object or signing

Follow-up: No real token obtained or used; endpoint reachability and provider authorization unresolved; no plaintext private-key disclosure or accepted TLS session established; nonnull wrapper is not proof of usable token object or signing

SVC-025 — RSD certificate-query reply callback accepts null result-string return and feeds a TLS verification adapter

Status: requires investigation
Retained source: publication/README.md:654 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED observation; impact UNKNOWN
Subsystem analysis: usb-and-services

Evidence: Stage5O exact-cache query and reply branches0x7ff814639d77/0x7ff814639e21; TLS adapter0x7ff81463e98c; byte and selector rechecks

Observation: RSD certificate-query reply callback accepts null result-string return and feeds a TLS verification adapter

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Server producer returns OK/ERROR; adverse reply producer endpoint control exact API handling and accepted transport remain unestablished; no bypass or severity claimed

Follow-up: Server producer returns OK/ERROR; adverse reply producer endpoint control exact API handling and accepted transport remain unestablished; no bypass or severity claimed

SVC-026 — AppleKeyStore request selects SEP token/session classes; local key implementation selected through typed nonzero current-task entitlement gate unless explicit ctkdConnection exists

Status: bounded
Retained source: publication/README.md:679 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5P exact constants and class/selector pointers; canUseSEPLocally0x7ff813c68f86; entitlement query0x7ff813c69003 and flag store0x7ff813c6909f;1376 selected instructions byte-checked

Observation: AppleKeyStore request selects SEP token/session classes; local key implementation selected through typed nonzero current-task entitlement gate unless explicit ctkdConnection exists

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Routing gate is not complete key-use authorization; sik.access failure only logs in examined block; SVC-027/028 trace constructors and retry/parameters; server/AKS rights and hardware backing unresolved

Follow-up: Routing gate is not complete key-use authorization; sik.access failure only logs in examined block; SVC-027/028 trace constructors and retry/parameters; server/AKS rights and hardware backing unresolved

SVC-027 — Concrete SEP key constructors distinguish unknown identifiers from denied system keys; reference-key signing checks AKS status; remote attributes use synchronous CTKD IPC

Status: bounded
Retained source: publication/README.md:709 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5Q30 functions2538 byte-checked instructions;93 pointer chains15 CFStrings; system-key entitlement and caller route; AKS blob/sign results; CTKD Mach service and required reply fields

Observation: Concrete SEP key constructors distinguish unknown identifiers from denied system keys; reference-key signing checks AKS status; remote attributes use synchronous CTKD IPC

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Client checks do not prove server caller authorization or backend ACL enforcement; no actual token import signing identity request or accepted transport; operation-block caller mapping and ARM equivalence remain open

Follow-up: Client checks do not prove server caller authorization or backend ACL enforcement; no actual token import signing identity request or accepted transport; operation-block caller mapping and ARM equivalence remain open

SVC-028 — Deferred token object is reconstructed before operation; registered-token errors permit one guarded retry; authentication handle and ACL/caller-group intersection reach AKS parameters

Status: bounded
Retained source: publication/README.md:742 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5R6 Security and17 CryptoTokenKit functions;1398 byte-checked instructions83 pointer chains10 CFStrings; ensureTokenObject and retry predicates; externalizedContext requirement; cag membership and AKS parameter keys1/3

Observation: Deferred token object is reconstructed before operation; registered-token errors permit one guarded retry; authentication handle and ACL/caller-group intersection reach AKS parameters

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: No live credential context or key used; operation blocks server audit-token checks context validation AKS backend and ARM remain unresolved; no unrestricted-access or authentication-bypass claim

Follow-up: No live credential context or key used; operation blocks server audit-token checks context validation AKS backend and ARM remain unresolved; no unrestricted-access or authentication-bypass claim

SVC-029 — CTKD passes the current XPC connection to a new local key; shared key-cache hits compare object ID and auth context without an explicit caller or force-session comparison

Status: bounded; requires investigation
Retained source: publication/README.md:769 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5S 11 CTKD functions832 instructions10 original methods47 references; local initializer51 instructions4 pointer chains; four inventory-matched files

Observation: CTKD passes the current XPC connection to a new local key; shared key-cache hits compare object ID and auth context without an explicit caller or force-session comparison

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Context binding and availability; server-instance scope; retained-caller and AKS authorization unresolved; no cross-client key use or bypass demonstrated

Follow-up: Context binding and availability; server-instance scope; retained-caller and AKS authorization unresolved; no cross-client key use or bypass demonstrated

SVC-030 — AKS setter removes prior parameter before replacement validation; import/signing wrappers check preparation results and propagate operation status

Status: bounded
Retained source: publication/README.md:791 (explicit ID in source narrative)
Related public data: No independent per-ID dataset is published; see the scoped evidence description below.
Evidence level: VERIFIED (bounded static or measured observation)
Subsystem analysis: usb-and-services

Evidence: Stage5T4body functions plusentry thunk390instructions excluding11padding bytes; original internal symbols

Observation: AKS setter removes prior parameter before replacement validation; import/signing wrappers check preparation results and propagate operation status

Interpretation: Prior scoped conclusion retained; see status and limit

Security relevance: See linked finding context; not independently re-rated in this segment

Confidence field: Unknown in this new field; prior status/evidence classification preserved

Limit: Ignored setter status is a caller review question; backend authorization/context binding and external import targets unresolved; no unauthorized key use demonstrated

Follow-up: Ignored setter status is a caller review question; backend authorization/context binding and external import targets unresolved; no unauthorized key use demonstrated