Skip to main content
Run any Skill in Manus
with one click

apple-vuln-research-apple-silicon-kernel-layout

Stars5
Forks0
UpdatedMay 31, 2026 at 23:28

Find the correct arm64e kernel and per-SoC kernelcache for a research target on Apple Silicon macOS. Use when: (1) `/System/Library/Kernels/kernel` reports as `Mach-O 64-bit executable x86_64` on an Apple Silicon Mac and you wonder which binary the system actually boots; (2) you need the per-SoC arm64e kernel for a specific Mac model (t8140 = A18 Pro / MacBook Neo, t8103 = M1, t8112 = M2, t6000/t6020/t6030/t6031/t6041/t6050 = M-Pro/ Max/Ultra families, t8122/t8132 = newer A-series in Mac, t8142 = next-gen MacBook Air, vmapple = virtualization); (3) you need the monolithic prelinked kernelcache that the BootROM actually loads (it's NOT at /System/Library/Kernels and NOT named "kernel" — it's at /System/Volumes/Preboot/<UUID>/restore/kernelcache.release.macNg where macNg is a board-id, e.g. mac17g for Mac17,5); (4) you took a "pre-update kernel snapshot" by copying /System/Library/Kernels/ kernel and a diff agent told you it's the wrong architecture; (5) you need to know whether two Mac models share a kernel bu

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly