Unsigned requests are sent directly to Apple APIs. No fallback, no integrity checks. Replay and downgrade attacks are possible.
Includes syslog evidence + PoC sketch: https://github.com/JGoyd/ams-failopen
Not theoretical — this was observed live in the wild.