Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
@Sh3ldon IMac16,2? If so, the only root patches you need for Sequoia should be Wi-Fi. If I were you, I would create an Open Core EFI with OCLP 2.4.1, I'd modify the config.plist to disable injection and blocking of the Wi-Fi kexts, I'd change SIP (csr-active-config) to <00000000>) and then I would install macOS Sequoia.

You should be able to boot macOS Sequoia with this modified Open Core EFI, use the Mac connected to wired Ethernet without OCLP root patches.

If you don't know how to do any of that, this isn't the thread to discuss the steps. Start a new thread and ping me. We can experiment together, since I don't have your iMac to test.

EDIT: If you must have Wi-Fi, I think you know my opinion.
 
  • Like
Reactions: BillyJoeJimBob
These are rather difficult times for security regardless. Here are some points for and against.

1. The attack surface might in some ways be smaller for an OCLP patched version of MacOS than the non-OCLP versions run by most people

2. Having said that, as I understand the current state of OCLP, the weak spot with MacOS post Ventura is likely Wifi as the latest version that uses native Wifi is Ventura, so if you are ok with running that for a while that is an option probably still with some security patching if Apple does that.

3. the state of current US tech and the general situation might all in all be worse regardless for security and a counter intuitive take is that older OS may even be safer for a while as things are, as new backdoors and such will probably not be added to an older OS.

4. For banking and using public wifi on later OS versions including Sequoia there are two options:
Use an USB wifi device or an ethernet adapter. That should keep the system safer as wifi should not need patching. Might need some tweaks when patching and I am not sure OCLP will handle that for you, have not done that myself, but some people are doing it with some degree of success. Patched wifi doing banking on a public wifi is skywriting.

5. Linux is a good choice these days and half of my Macs are already on Ubuntu. Probably bought my last Mac but who knows..
Good luck.
 
That's a tuff choice, and I would probably lean towards no longer supported system if you had too. However I think there is a third option and it's linux Mint. I run it on my 2012 Mac mini and it was pretty easy to get set up. There is also plenty of help on line if you get stuck
Thanks for the reply, but I'd like to stay in the Apple ecosystem if possible. I know Linux has made great strides in simplicity, but I'd prefer to choose the lesser of two evils and stay on Mac. Thanks for the reply, anyway.
 
@Sh3ldon IMac16,2? If so, the only root patches you need for Sequoia should be Wi-Fi. If I were you, I would create an Open Core EFI with OCLP 2.4.1, I'd modify the config.plist to disable injection and blocking of the Wi-Fi kexts, I'd change SIP (csr-active-config) to <00000000>) and then I would install macOS Sequoia.

You should be able to boot macOS Sequoia with this modified Open Core EFI, use the Mac connected to wired Ethernet without OCLP root patches.

If you don't know how to do any of that, this isn't the thread to discuss the steps. Start a new thread and ping me. We can experiment together, since I don't have your iMac to test.

EDIT: If you must have Wi-Fi, I think you know my opinion.
Thanks @deeveedee for the reply. I'm not a tech expert, but thanks to Mr. Macintosh's videos, I was able to install Sequoia on my late 2015 iMac, which supports up to Monterey. I don't use Wi-Fi, so I'm connected to the network via Ethernet. But I was able to do it because the OCLP installer did everything without requiring any special modifications: I made the USB stick according to the instructions, and everything went smoothly. I have 24GB of RAM, and Sequoia works well, but most importantly, it lets me use updated Safari. I'd have a hard time switching to Firefox or Chrome, but if there were no alternative, I'd adapt.

Screenshot 2026-03-24 alle 17.43.44.png


I am running on Sequoia 15.7.4.

Thanks!

Ah, I forgot: I have 1TB SSD inside that works very well and I have NordVPN Threat Protection Pro to protect the Mac.
 
Last edited:
One last thing: I could use my iPhone, which runs iOS 26, for online banking, but I find the process quite cumbersome. I find it easier to type on the physical keyboard than on the iPhone's. Sorry if I've gone off topic with these questions; if so, please move these posts to a more appropriate location.
 
@Sh3ldon I think I misunderstood your request. My instructions were intended to preserve the macOS security that can be compromised with a default OCLP install. Your procedure introduces the security issues that I thought you wanted to avoid.

Glad it's working the way you want it to.

If you want to discuss more specifics of your Mac, I suggest that you create a new thread that doesn't go off-topic here.
 
  • Like
Reactions: Sh3ldon
@Sh3ldon I think I misunderstood your request. My instructions were intended to preserve the macOS security that can be compromised with a default OCLP install. Your procedure introduces the security issues that I thought you wanted to avoid.

Glad it's working the way you want it to.

If you want to discuss more specifics of your Mac, I suggest that you create a new thread that doesn't go off-topic here.
If You and other People agree (and the moderators too) we should continue in this thread I've already opened.
 
Anthropic's latest AI has identified zero-day vulnerabilities in major operating systems. OCLP root patches enable modern macOS support on legacy Macs by injecting old frameworks from previously-released macOS operating systems into the new macOS versions. These OCLP root patches extracted from old macOS versions are no longer being updated by Apple. This means that security vulnerabilities from the old versions of macOS may now exist in OCLP-patched versions of macOS.
 
Anthropic's latest AI has identified zero-day vulnerabilities in major operating systems. OCLP root patches enable modern macOS support on legacy Macs by injecting old frameworks from previously-released macOS operating systems into the new macOS versions. These OCLP root patches extracted from old macOS versions are no longer being updated by Apple. This means that security vulnerabilities from the old versions of macOS may now exist in OCLP-patched versions of macOS.
"AI" aiding bad actors to find attack surfaces.
How utterly predictable. We discussed this here just a few months back.
 
  • Like
Reactions: MacHeritage
Intersting read, especiall the "SIP Bypass" section:


Might be a good idea to disable IPv6 and only use IPv4 to have NAT as a barrier between you and the rest of the world.
 
Anthropic's latest AI has identified zero-day vulnerabilities in major operating systems. OCLP root patches enable modern macOS support on legacy Macs by injecting old frameworks from previously-released macOS operating systems into the new macOS versions. These OCLP root patches extracted from old macOS versions are no longer being updated by Apple. This means that security vulnerabilities from the old versions of macOS may now exist in OCLP-patched versions of macOS.
That’s not true. Vulnerable drivers allow an attacker to abuse vulnerabilities in the driver itself, while the operating system is completely patched. It’s like to install a GPU driver from 2011 on Windows 10 - it may work, but it will be extremely vulnerable to modern security threats.
Furthermore, most attackers want the easy path, not to reverse engineer drivers to exploit them. Most attackers go after finding vulnerabilities in the operating system, not drivers. Most attackers who abuse macOS drivers are APTs and state sponsored actors. On macOS, BYOVD (Bring your own vulnerable driver) doesn’t really work, and that’s the only path non-APTs exploit drivers. Most malware don’t even go after drivers, for example a macOS trojan doesn’t need a vulnerable driver, it needs a vulnerability in macOS itself.
Maybe some hackers do exploit drivers to gain admin rights, but mostly this kind of threats don’t exist on macOS, so you’re safe.
Just reverse engineering a driver is a huge effort, let alone to exploit it.
 
  • Like
Reactions: houser
@Sh3ldon IMac16,2? If so, the only root patches you need for Sequoia should be Wi-Fi. If I were you, I would create an Open Core EFI with OCLP 2.4.1, I'd modify the config.plist to disable injection and blocking of the Wi-Fi kexts, I'd change SIP (csr-active-config) to <00000000>) and then I would install macOS Sequoia.

You should be able to boot macOS Sequoia with this modified Open Core EFI, use the Mac connected to wired Ethernet without OCLP root patches.

If you don't know how to do any of that, this isn't the thread to discuss the steps. Start a new thread and ping me. We can experiment together, since I don't have your iMac to test.
More info might be helpful
 
That’s not true. Vulnerable drivers allow an attacker to abuse vulnerabilities in the driver itself, while the operating system is completely patched.
You're contradicting yourself. From the user's perspective, there is no difference between exploiting vulnerabilities in the OS and exploiting vulnerabilities in drivers within the OS.

Also, your initial statement of "That's not true" implies an absolute which you then proceed to justify with "Mostly" and "Most" arguments. You yourself are stating that there are exceptions to your own statement.

This makes no sense: "but mostly this kind of threats don’t exist on macOS, so you’re safe." If you want to say that the risks are low, I wouldn't disagree with that. All we're stating in this thread is that the risks exist and that the exploit is possible.

EDIT: In the world of computer security, known vulnerabilities are routinely addressed without a known exploit. The definition of "Known Vulnerability" in the computer security world is as follows:
  • Known vulnerability: A security weakness has been identified and documented (e.g., a CVE), but there may be no evidence that attackers are exploiting it.
Depending on the use case, the known vulnerability is still a concern. For example, for PCI compliance, this type of CVE is very common:

A PCI-related security bulletin could say:

CVE-XXXX-XXXX — Critical vulnerability in Product X. No known exploitation at this time. Vendor patch available.

The CVE never says "it's hard for an attacker to exploit this, so you're safe."

See @houser 's statement here. It's only going to get easier for even the most junior hacker to exploit vulnerabilities.
 
Last edited:
  • Like
Reactions: jbn858273
@Albert Müller Here's an example of a driver vulnerability that might exist in an OCLP-patched Mac as stated by ChatGPT:

An OCLP installation that substitutes an unmaintained Ventura Wi-Fi component for the current Apple component creates a credible additional layer-2 attack surface that a natively supported Mac running the same macOS release does not have.

More precisely:

Any vulnerability in the Ventura Wi-Fi component that Apple subsequently fixed in Sonoma/Sequoia, but which remains present in the OCLP-carried component, represents a vulnerability unique to the OCLP configuration relative to a native installation.
And because Wi-Fi operates below IP, such a vulnerability could be remotely exploitable by an attacker within radio range, potentially before normal network-level security controls become relevant.

That's an important security limitation of OCLP that is easy to overlook when someone says “I'm running the latest Sequoia security update, therefore I'm fully patched.” The OS version alone doesn't establish that the actual wireless attack surface is patched.
 
@Albert Müller Here's an example of a driver vulnerability that might exist in an OCLP-patched Mac as stated by ChatGPT:

An OCLP installation that substitutes an unmaintained Ventura Wi-Fi component for the current Apple component creates a credible additional layer-2 attack surface that a natively supported Mac running the same macOS release does not have.

More precisely:


And because Wi-Fi operates below IP, such a vulnerability could be remotely exploitable by an attacker within radio range, potentially before normal network-level security controls become relevant.

That's an important security limitation of OCLP that is easy to overlook when someone says “I'm running the latest Sequoia security update, therefore I'm fully patched.” The OS version alone doesn't establish that the actual wireless attack surface is patched.

Yes, this is what I meant. Driver vulnerabilities are independant from the operating system's. Using an 11 yr old WiFi driver - that one is vulnerable to modern security threats. If an attacker could find a security flaw in the driver on Windows, on macOS I'm not 100% sure it would work, they could gain ring 0 access. On macOS I haven't seen yet a CVE documenting gaining access to ring 0.
 
Last edited:
  • Like
Reactions: TimothyR734
You're contradicting yourself. From the user's perspective, there is no difference between exploiting vulnerabilities in the OS and exploiting vulnerabilities in drivers within the OS.

Also, your initial statement of "That's not true" implies an absolute which you then proceed to justify with "Mostly" and "Most" arguments. You yourself are stating that there are exceptions to your own statement.

This makes no sense: "but mostly this kind of threats don’t exist on macOS, so you’re safe." If you want to say that the risks are low, I wouldn't disagree with that. All we're stating in this thread is that the risks exist and that the exploit is possible.

EDIT: In the world of computer security, known vulnerabilities are routinely addressed without a known exploit. The definition of "Known Vulnerability" in the computer security world is as follows:
  • Known vulnerability: A security weakness has been identified and documented (e.g., a CVE), but there may be no evidence that attackers are exploiting it.
Depending on the use case, the known vulnerability is still a concern. For example, for PCI compliance, this type of CVE is very common:

A PCI-related security bulletin could say:



The CVE never says "it's hard for an attacker to exploit this, so you're safe."

See @houser 's statement here. It's only going to get easier for even the most junior hacker to exploit vulnerabilities.

You're right.
Having no evidence of exploiting it doesn't mean it is unnecessary to fix a flaw.
 
On macOS I haven't seen yet a CVE documenting gaining access to ring 0.
No one is writing CVEs for OCLP-patched Macs.

I wonder what CVEs would be generated for Macs that had
  • Disabled SIP
  • Broken APFS Seal
  • Root patches that had not been recertified by a FIPS validated 3rd-party
  • Disabled Secure Boot
We're fortunate that macOS implements multiple layers of security, so that OCLP patches can still be considered relatively low risk, but the point of this thread is that the risk is non-zero.

EDIT: The risk only increases as the root patches age (the old Apple frameworks are not being updated) and junior hackers become more sofisticated with AI. Not to mention your discovery that T2 Macs may need SIP completely disabled for macOS Tahoe.
 
Last edited:
  • Like
Reactions: TimothyR734
No one is writing CVEs for OCLP-patched Macs.

I wonder what CVEs would be generated for Macs that had
  • Disabled SIP
  • Broken APFS Seal
  • Root patches that had not been recertified by a FIPS validated 3rd-party
  • Disabled Secure Boot
We're fortunate that macOS implements multiple layers of security, so that OCLP patches can still be considered relatively low risk, but the point of this thread is that the risk is non-zero.

EDIT: The risk only increases as the root patches age (the old Apple frameworks are not being updated) and junior hackers become more sofisticated with AI. Not to mention your discovery that T2 Macs may need SIP completely disabled for macOS Tahoe.
Also, the OCLP app has its own attack surface. How large is the attack surface depends on the developers mostly.
 
  • Like
Reactions: TimothyR734
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.