Checked all the time, it's a Merkle tree structure.
You can modify the seal when the Sealed System Volume feature is off. (which requires Secure Boot to be set to Permissive Security, and FileVault to be off at the time of disabling)
You can modify the seal when the Sealed System Volume feature is off. (which requires Secure Boot to be set to Permissive Security, and FileVault to be off at the time of disabling)
⇒ there may of course be bugs, but Apple’s intent is there isn’t any way for malware to do that