The Tivoization clause applies to hardware vendors, with hardware covered by GPLv3's definition of a "User Product".
Ubuntu itself isn't a valid comparison, because it's not a physical product. And computers that ship with Ubuntu don't violate GPLv3, because you can install anything you want on them without restriction.
The license incompatibility isn't intrinsic to MacOS, it's intrinsic to Apple's computers. Which ship with MacOS.
If MacOS included GPLv3 software, Apple wouldn't be able to pre-install it unless they provided all users with signing keys to install their own modified versions of the GPLv3 software on-target. Check out the GPLv3's "User Product" and "Installation Information" sections for more details - they're written in plain English, and are pretty clear.
Basically - if you want to sell hardware that comes with any GPLv3 software installed, then you need to empower your customers to replace or modify that software on their devices. Not the entire OS, mind. Just the pieces that are GPLv3. But that requirement prevents a hardware vendor from doing something like saying "I'll only boot a signed/verified root filesystem" or "The rootfs (or even just /usr) is read-only to everything except for signed OS updates".
So it's not that shipping GPLv3 Make/Coreutils would infect MacOS and require Apple to release the MacOS source. Instead, it's that shipping GPLv3 Make/Coreutils would prevent Apple from locking down their computers and code-signing MacOS (unless they provided the OS-level signing keys on request).