Future work includes exploring whether checkm8-like bugs exist in Apple Silicon bootROMs and developing runtime detection for T2 compromise.

A lightweight, command-line tool known for being extremely fast and reliable. It is frequently used by researchers to "pwn" the DFU state before booting a custom ramdisk [4].