For years, Apple silicon Macs shared a single firmware image per macOS release, with iBoot and mBoot versions moving in lockstep across every supported operating system. A Mac’s firmware number was a reliable fingerprint of its software state, until recently.
The Eclectic Light Company’s Howard Oakley caught the break while maintaining virtual machines. Macs updated to macOS Sequoia 15.7.9 and Sonoma 14.8.9 before August 17 carry mBoot firmware 18000.161.9. Macs updated to the exact same builds after that date receive 18000.161.10 instead. The macOS version and build number never change.
Apple shipped the newer firmware only with macOS Tahoe 26.6.2 on August 17, then quietly started attaching it to the legacy security updates as well. Nothing about the swap appears in Apple’s security release notes, and the affected updates saw no build increment. Oakley rechecked his virtual machines on August 28 and confirmed the divergence.
The practical risk is transparency. Two identical Macs running the same macOS build can now hold different versions of the trusted boot firmware, with no official explanation. Users who verify firmware with third-party tools will see mismatches, and Oakley says Apple’s silence is so complete that a plausible reading, however wrong, is that an attacker meddled with the update.
The finding also weakens a guarantee Mac owners took for granted. A given macOS release no longer pins down the firmware that arrives with it, and installing the same update days apart can leave different boot code behind. Oakley calls the episode a silent rewrite of the updater, and suggests anyone who tracks firmware for security reasons treat the numbers with caution.