Apple has firmware restore features in ROM. I would also assume (hope?) that there’s a procedure to enter the ROM-based restore that is impossible to intercept in software (maybe holding the power button for 10 seconds initiates a hardware reset into the ROM.)
There is.
everything is signed.
should not be even remotely possible
Should. But we are talking about software vulnerabilities here.
It means that things do not work as intended.
All code is signed on Apple’s platforms. Most exploits have a codesigning bypass of some sort.