RedPatch
Headlines refreshed Sun Oct 11, 11:45 AM ET (1 h ago) · content checked against vendor docs

⌘ macOS security

macOS, locked down.

This guide covers the two newest macOS releases as of October 2026. macOS Golden Gate 27 shipped on September 14, 2026 and runs only on Apple silicon Macs. macOS Tahoe 26 is the release before it and still gets security updates. Each tip is marked for everyday users, power users or admins, and links to Apple's own docs or the tool maker's docs. Check commands only read settings. Commands that change anything are listed separately and need you to run them on purpose.

33 tips · 15 tools · every one sourced

Latest macOS advisories

  1. KEV: CVE-2015-5477 — ISC BIND: ISC BIND Data Processing Errors VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
  2. KEV: CVE-2016-3081 — Apache Struts: Apache Struts Command Injection VulnerabilityCISA Known Exploited Vulnerabilities (KEV) · Oct 8
  3. App Store Connect API 4.5.1Apple Developer Releases (OS updates) · Oct 6
  4. Hello Developer: October 2026Apple Developer news · Oct 6

All macOS headlines →

1. Patch first: updates and Background Security Improvements

Stay on a supported macOS and install updates fast

everyone

On 2026-09-14 Apple released Golden Gate 27, Tahoe 26.7 and Sequoia 15.8 together, followed by 27.0.1, 26.7.1 and 15.8.1 on 2026-09-28. Sonoma was not part of the September release. An unpatched Mac is the easiest Mac to break into.

Go to Apple menu > System Settings > General > Software Update. Turn on Automatic Updates, then click the More Info button next to it and make sure "Install system data files and security updates" is on. Apple's security releases page lists what each update fixes.

Check — read-only
sw_vers; softwareupdate --list
Changes your system
sudo softwareupdate --install --all --restart

Source: Apple security releases

Turn on automatic Background Security Improvements

everyone

Starting with macOS 26.1, Background Security Improvements (BSI) deliver small security fixes between full updates, for parts such as Safari, WebKit and other system libraries. A Safari fix can take effect as soon as you relaunch Safari; the rest applies at the next restart.

Go to System Settings > Privacy & Security > Background Security Improvements and turn on Automatically Install. In rare cases of compatibility problems, Apple may remove a BSI and ship the fix in a later update.

Check — read-only
sw_vers -productVersion

Source: Background Security Improvements in Apple operating systems

Fleet: move update enforcement to declarative management

admin

Apple says legacy software update management no longer functions in all 27.0 operating systems. That includes software update commands and queries, recommended cadence settings, and restrictions such as deferrals and Background Security Improvements.

Use your MDM's declarative software update configuration to set target versions and enforcement deadlines. Use it to decide whether BSIs install automatically and whether users may remove them.

Source: Install and enforce software updates for Apple devices

Know about silent background security data updates

power user

XProtect signatures, Gatekeeper configuration data and other security-configuration updates install in the background, separately from macOS updates. If you turn that option off, your Mac falls behind without telling you.

In Tahoe and later, leave "Install system data files and security updates" on under Software Update > Automatic Updates > More Info. To see what has installed, hold Option, choose Apple menu > System Information, then Software > Installations.

Check — read-only
softwareupdate --history | tail -20

Source: About background updates in macOS

2. Encryption, boot chain and system integrity

Turn on FileVault

everyone

On Apple silicon the drive is always encrypted, but FileVault adds the step that keeps anyone from decrypting your data without your login password.

Go to System Settings > Privacy & Security > FileVault and turn it on. Choose to let your iCloud account unlock the disk, or create a recovery key and keep it somewhere safe that is not with the Mac.

Check — read-only
fdesetup status
Changes your system
sudo fdesetup enable

Source: Protect data on your Mac with FileVault

Escrow FileVault recovery keys in MDM

admin

Admins need a way to recover a locked managed Mac that doesn't depend on the user writing down a key. On macOS 26.4 and later, FileVault turns on during Setup Assistant by default, so escrow is what you control.

Use your MDM's FileVault settings to escrow the personal recovery key and stop users from turning FileVault off. Use fdesetup to confirm a key exists and to rotate it if it is exposed.

Check — read-only
sudo fdesetup haspersonalrecoverykey; sudo fdesetup list
Changes your system
sudo fdesetup changerecovery -personal

Source: Manage FileVault with device management

Keep secure boot at Full Security

power user

Apple silicon Macs check every boot stage against Apple's signatures. Full Security only allows booting the latest signed macOS that was available at install time. Reduced Security allows older macOS versions and kernel extensions.

Only lower this if you truly need third-party kernel extensions. To check or change it, shut down, press and hold the power button until Startup Options appears, choose Options, then Utilities > Startup Security Utility, and leave Full Security selected.

Check — read-only
sudo bputil -d

Source: Boot process for a Mac with Apple silicon

Leave System Integrity Protection on

everyone

System Integrity Protection (SIP) limits what even the root user can change in protected parts of macOS, such as /System, /usr, /bin and /sbin. Software that gets your admin password still can't overwrite those files.

Don't turn SIP off. If a tool tells you to disable SIP, don't use that tool.

Check — read-only
csrutil status; csrutil authenticated-root status

Source: About System Integrity Protection on your Mac

Turn on Find My Mac so Activation Lock protects it

everyone

With Activation Lock, your Apple Account password is needed before anyone can turn off Find My, erase the Mac, or reactivate and use it.

Go to System Settings > [your name] > iCloud, click See All, then Find My Mac, and turn it on. Activation Lock needs two-factor authentication and, on Apple silicon, Full Security. Turn off Find My before you sell or give away the Mac.

Check — read-only
system_profiler SPHardwareDataType | grep -i 'activation lock'

Source: Activation Lock for Mac

3. Stop bad code: Gatekeeper, notarization, XProtect

Only open apps from the App Store or identified, notarized developers

everyone

Gatekeeper checks that apps from outside the App Store come from an identified developer, are notarized by Apple and haven't been altered. Apple can also revoke an app it later finds to be malicious.

Go to System Settings > Privacy & Security, scroll to Security, and under "Allow apps downloaded from" choose App Store and identified developers (or App Store only). To open a blocked app, you have to try opening it, then click Open Anyway in Privacy & Security. Only do that when you know exactly where the app came from.

Check — read-only
spctl --status; spctl --assess --verbose /Applications/Safari.app

Source: Safely open apps on your Mac

Check an app's signature before you trust it

power user

Malware often comes unsigned, ad hoc-signed or signed by an unexpected developer. Checking the Team ID shows who really built the app.

Run the check commands on the downloaded .app before you open it. Look for source=Notarized Developer ID and a Team ID you recognize.

Check — read-only
codesign -dv --verbose=4 /path/to/App.app; spctl -a -vvv -t install /path/to/App.app

Source: Gatekeeper and runtime protection in macOS

Let XProtect do its job

everyone

XProtect is macOS's built-in antivirus. It uses YARA signatures that Apple updates on its own schedule, blocks known malware when an app first launches or changes, and moves it to the Trash.

No setup is needed. Keep the background security updates option on. The xprotect command shows the installed signature version and can trigger an update.

Check — read-only
xprotect version; xprotect status
Changes your system
sudo xprotect update

Source: Protecting against malware in macOS

Fleet: block or allow binaries with declarative rules (macOS 27)

admin

On supervised Macs with macOS 27, declarative device management can allow or deny apps and binaries. Rules match on CD Hash, Team ID, Signing ID, path prefix or signing state. Unsigned, ad hoc-signed and development-signed binaries are denied even when the list is empty.

Deploy the allow/deny apps and binaries configuration from your MDM. Deny mode blocks only what you list; allow mode runs only what you list plus essential system binaries. If one Mac gets both, the more restrictive mode wins. Start in deny mode, then move to allow mode once you have an inventory.

Source: Allow and deny apps and binaries on Apple devices

Pick up the other enterprise changes in Golden Gate

admin

Golden Gate lets Platform SSO sign in with your identity provider over OpenID at FileVault unlock, the Lock Screen and the login window, including multi-factor and QR code sign-in. It can require Touch ID or Apple Watch at login, adds a consolidated privacy consent prompt, and lets MDM restrict Siri AI and Visual Intelligence. Apps can no longer read the local TCC database directly.

Read Apple's enterprise What's New for Golden Gate. Update your MDM baselines before you approve the upgrade for the fleet.

Source: What's new for enterprise in macOS Golden Gate 27

4. Network exposure: firewall, stealth mode, sharing

Turn on the built-in application firewall

everyone

The firewall blocks unwanted incoming connections to apps and services.

Go to System Settings > Network > Firewall and turn it on. You may need to scroll down to see it.

Check — read-only
/usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate
Changes your system
sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on

Source: Block connections to your Mac with a firewall

Turn on stealth mode

everyone

In stealth mode the Mac doesn't answer probing requests such as ping, so it is harder to find on hotel or café Wi-Fi.

Go to System Settings > Network > Firewall > Options and turn on Enable stealth mode. Consider turning on Block all incoming connections when you are on untrusted networks.

Check — read-only
/usr/libexec/ApplicationFirewall/socketfilterfw --getstealthmode; /usr/libexec/ApplicationFirewall/socketfilterfw --getblockall
Changes your system
sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setstealthmode on

Source: Change Firewall settings on Mac

Turn off sharing services you don't use

everyone

Every sharing service that is on, such as Remote Login (SSH), Screen Sharing, File Sharing or Remote Management, opens a port someone can reach. Sharing services can connect through the firewall when turned on.

Go to System Settings > General > Sharing and turn off anything you don't need. Then list the listening ports to confirm.

Check — read-only
sudo lsof -nP -iTCP -sTCP:LISTEN; sudo systemsetup -getremotelogin

Source: Change Sharing settings on Mac

Use iCloud Private Relay on public networks

everyone

Private Relay encrypts traffic leaving your device and sends it through two separate relays, so no one can use your IP address, location and browsing to build a profile of you.

Go to System Settings > [your name] > iCloud > Private Relay and turn it on (requires iCloud+). It must be turned on on each device. Per network, "Limit IP address tracking" must stay on for it to work.

Source: Use iCloud Private Relay on Mac

5. Accounts, passwords and iCloud

Do daily work in a standard account, not an admin account

power user

Malware runs with your rights. A standard user can't add other users or change other users' settings, and has to ask for an admin password for system-wide changes. Apple also warns never to set up automatic login for an administrator.

Create a separate administrator account in System Settings > Users & Groups. Then click the info button next to your daily account and turn off Allow this user to administer this computer.

Check — read-only
id -Gn | tr ' ' '\n' | grep -x admin; dscl . -read /Groups/admin GroupMembership

Source: Change Users & Groups settings on Mac

Use the Passwords app and switch to passkeys

everyone

The Passwords app keeps passwords, passkeys and verification codes in one place and shows Security Recommendations for weak, reused or leaked passwords. A passkey can't be phished or leaked by a website breach.

Open the Passwords app and fix everything it lists under Security. When a site offers a passkey, accept it.

Source: Passwords User Guide for Mac

Turn on Advanced Data Protection for iCloud

power user

With Advanced Data Protection (ADP), most iCloud data, including backups, Photos, Notes and iCloud Drive, is end-to-end encrypted, so only your trusted devices hold the keys.

Update your devices first. Then go to System Settings > [your name] > iCloud > Advanced Data Protection > Turn On, and follow the steps to review your recovery methods. iCloud.com web access is off by default while ADP is on.

Source: How to turn on Advanced Data Protection for iCloud

Protect your Apple Account with security keys

power user

Your Apple Account controls Find My, Activation Lock and iCloud. Physical security keys stop attackers from phishing or intercepting your second factor.

Get at least two FIDO Certified security keys. Go to System Settings > [your name] > Sign-In & Security > Two-Factor Authentication > Security Keys and add them. If you lose all trusted devices and keys you can be locked out for good.

Source: About Security Keys for Apple Account

Lock the screen quickly and require the password right away

everyone

An unlocked, unattended Mac gets past every other control on this list.

Go to System Settings > Lock Screen and set Require password after screen saver begins or display is turned off to Immediately. Set short display-off times on battery and power adapter. Use Control-Command-Q to lock the screen.

Check — read-only
sysadminctl -screenLock status

Source: Change Lock Screen settings on Mac

6. Privacy permissions and persistence

Review privacy permissions every month

everyone

macOS privacy controls (TCC) decide which apps can use your camera, microphone, screen recording, input monitoring, files and more. Malware tries hardest to get Accessibility and Full Disk Access.

Go to System Settings > Privacy & Security. Check Full Disk Access, Accessibility, Screen & System Audio Recording, Input Monitoring, Camera and Microphone, and remove anything you don't recognize.

Changes your system
tccutil reset All com.example.suspectapp

Source: Protecting app access to user data

Audit login items and background activity

everyone

Persistence is how malware survives a reboot. Login items and apps allowed to run in the background are listed in one place.

Go to System Settings > General > Login Items & Extensions. Review Open at Login and App Background Activity, and turn off anything you don't recognize. Also check Endpoint Security and Network extensions there.

Check — read-only
sudo sfltool dumpbtm | less; launchctl list | grep -v com.apple

Source: Change Login Items & Extensions settings on Mac

Fleet: approve background items and privacy permissions by profile

admin

If you pre-approve known agents by profile, users don't get trained to click Allow on everything.

Deploy a Managed Login Items (com.apple.servicemanagement) payload with rules matched on Team ID or bundle ID, plus a Privacy Preferences Policy Control payload for each managed tool. On Golden Gate, users are notified about apps given Accessibility by PPPC and can turn that off.

Check — read-only
sudo profiles show -type configuration

Source: Managed Login Items device management payload settings

Check for unknown configuration profiles and MDM enrollment

power user

A configuration profile can set up accounts, Wi-Fi, VPN and other settings, so a rogue one can redirect your traffic.

Go to System Settings > General > Device Management. Remove any profile you didn't install on purpose. On a managed Mac, ask IT before removing anything.

Check — read-only
profiles status -type enrollment; sudo profiles show -type configuration

Source: Use configuration profiles to standardize settings on Mac computers

Check accessory security on Apple silicon laptops

everyone

On Mac laptops with Apple silicon, new USB and Thunderbolt devices and SD cards must be approved before they can exchange data. Don't Allow still lets a device charge, which is the safe choice at public charging stations.

Go to System Settings > Privacy & Security > Accessories and set Allow accessories to connect to Ask for new accessories or Always ask.

Source: Use the ports on your Mac

7. High-risk users: Lockdown Mode

Use Lockdown Mode if you could be targeted by spyware

everyone

Lockdown Mode greatly reduces what an attacker can reach. It blocks most Messages attachments and link previews, some complex web technologies, configuration profiles and MDM enrollment, and on Apple silicon laptops needs the Mac unlocked plus your approval to connect an accessory.

Go to System Settings > Privacy & Security > Lockdown Mode > Turn On, then click Turn On & Restart. You can exclude trusted websites, apps or contacts, which lowers protection. Turn it on separately on each Mac.

Source: About Lockdown Mode

Know that Lockdown Mode blocks MDM

admin

A Mac in Lockdown Mode can't install configuration profiles or enroll in MDM or supervision. Admins should plan for that before users turn it on.

Turn Lockdown Mode on only on unmanaged Macs, or enroll the Mac first and test that your MDM workflows still work. Golden Gate MDM status reports now include Lockdown Mode status.

Source: About Lockdown Mode

8. Hardening and compliance at scale

Build your baseline with the macOS Security Compliance Project

admin

The NIST-led mSCP turns NIST 800-53, 800-171, CIS Benchmarks and the DISA STIG into ready-made profiles, scripts and documentation. mSCP 2.0, Release 27.0 covers macOS 27, and Tahoe Guidance Revision 3.0 covers macOS 26.

Clone the repo. Generate a baseline, for example CIS Level 1, and from it get the configuration profiles plus a compliance script that has check-only and fix modes. Run the check first.

Source: usnistgov/macos_security releases

Read the Apple Platform Security guide once a year

power user

It is Apple's official explanation of secure boot, the Secure Enclave, Data Protection, XProtect, privacy controls and Background Security Improvements. Use it to answer why a control works.

Read the web version. Re-read the sections that change after each major release.

Source: Apple Platform Security

Use the Endpoint Security API instead of kernel extensions

admin

Third-party security tools should use Apple's Endpoint Security framework, not kernel extensions, which need Reduced Security. Since macOS 15 these tools can also see Gatekeeper user-override events.

When you choose EDR or allowlisting tools, require Endpoint Security system extensions, and approve them by MDM.

Check — read-only
systemextensionsctl list; kmutil showloaded --list-only | grep -v com.apple

Source: Endpoint Security framework

Tools worth knowing

fdesetupbuilt-in

Built-in command that reports and manages FileVault status, users and recovery keys.

When: Confirm encryption is on, or rotate a recovery key that was exposed.

spctlbuilt-in

Built-in command for Gatekeeper status and checking an app against Gatekeeper policy.

When: Before opening a downloaded app, or to confirm Gatekeeper is on.

csrutilbuilt-in

Built-in command that reports System Integrity Protection and sealed system volume status.

When: Quick check that SIP and the sealed system volume are on.

socketfilterfwbuilt-in

Command-line control for the application firewall, at /usr/libexec/ApplicationFirewall/.

When: Script firewall and stealth mode checks across many Macs.

profilesbuilt-in

Built-in command that shows MDM enrollment and installed configuration profiles.

When: Look for rogue profiles, or confirm a Mac is enrolled.

xprotect / sfltool / bputilbuilt-in

Built-in commands. xprotect version and status show XProtect state, and xprotect update triggers an update. sudo sfltool dumpbtm lists background items. sudo bputil -d shows the Apple silicon boot policy.

When: Malware definitions check, persistence audit and boot security check.

LuLu (Objective-See)free

Free, open-source firewall that alerts on unknown outgoing connections (version 4.5.1).

When: When you want to see and block which apps phone home. The built-in firewall only filters incoming connections.

BlockBlock (Objective-See)free

Watches persistence locations and alerts when something installs itself to survive a reboot (version 2.5.2).

When: Always-on persistence alerting on personal or high-value Macs.

KnockKnock (Objective-See)free

Lists everything that is persistently installed, with signing status and VirusTotal checks (version 4.1.0).

When: One-off sweep when you suspect an infection, or a quarterly audit.

OverSight (Objective-See)free

Alerts when the microphone or webcam turns on, and tells you which process turned it on (version 2.4.0).

When: For people worried about covert audio or video capture.

ReiKey (Objective-See)free

Scans for and monitors keyboard event taps, which keyloggers use (version 1.4.2).

When: Checking for keyloggers, especially after you approve an Input Monitoring request.

Santa (North Pole Security)free + paid

Open-source binary authorization agent that allows or blocks binaries by hash, Team ID, Signing ID or certificate. It started at Google and is now maintained by North Pole Security.

When: Fleets that need allowlisting beyond the built-in macOS 27 rules, or that also run Macs on Tahoe.

osqueryfree

Open-source agent that lets you query OS state (processes, launchd, apps, SIP, FileVault) with SQL.

When: Fleet-wide inventory and detection queries, and evidence for compliance.

mSCP (macOS Security Compliance Project)free

NIST-led project that generates baselines, profiles and audit/fix scripts for CIS, NIST 800-53/171 and the DISA STIG.

When: Building or auditing a hardened macOS baseline for an organization.

Apple Platform Security guidefree

Apple's official technical reference for every platform security feature.

When: When you need to understand how a control actually works.

Other platforms

Go deeper

networks.jelia.nycHow the internet actually moves your data — packets, DNS, routing, TLS. waves.jelia.nycElectromagnetism explained — Wi-Fi, 2.4 GHz, Bluetooth and why RF leaks. lib.jelia.nycThe library — security, Linux, assembly and networking books on the shelf. blog.redpatch.usRedPatch field notes.