Got a tip for us?

Mac

Mac OS, Mac OS X, or macOS, is the operating system that resides on Apple’s desktop and portable computer lineup. Built upon a Unix core, it is easy to use yet highly advanced, extremely stable, and an excellent OS for productivity and creation. Browse through our articles to
look for something specific that is pertinent to the Mac operating system.

In a TidBITS article, Evaluating Wireless Security Needs: The Three L’s, Adam Engst laid out the three factors he considered relevant to determining one’s risk when it comes to Wi-Fi security. He called them the three L’s: likelihood (the probability that someone will violate your security), liability (the cost—financial or otherwise—that you’d incur if a security breach happened), and lost opportunity (what you lose in terms of time and convenience by implementing stronger security). That article is still well worth a read almost two decades later.

Times, technologies, and threats change, but some people still face greater risks than others. If you can assess your own level of risk soberly, you’ll be able to take appropriate measures—neither too weak nor too strong.

The risk for most people

Years ago, it made more sense for nearly all Mac owners to consider their susceptibility to outside attack: how likely were you to visit sketchy sites, download applications that might contain Trojan horses, be infected by malware by visiting a site or running software, or even configure a network sharing setting that allowed people on the internet to scan and find weaknesses they could use to potentially copy data from your Mac, or worse. iPhone and then iPad users had fewer risks because of how iOS and iPadOS were constructed and locked down, but external attacks remained the central problem for them.

That profile changed considerably by the late 2010s. The biggest risk that most Apple users have faced since then—no matter their specific Apple hardware—comes from phishing and social engineering.

Phishing describes when someone impersonates a person, group, or website in the hopes you will click through and be infected by malware or enter login credentials. Phishers want your personal data, preferably financial information, such as your credit card number, expiration date, and verification code. They try to offer credible-looking security warnings and fraudulent webpages where you enter payment information or credentials they can use to access your bank and other accounts.

Social engineering is when people attempt to convince you to do something harmful to your device—and compromise your security and privacy. A common scam is that you visit a website and are redirected to another site (via malicious advertising or injected code) that claims your computer, phone, or tablet is infected and urges you to call a number. Calling that number leads you to a boiler room in which the other parties try to get you to install remote access software and sign up for expensive, hard-to-cancel tech services—or worse.

There are also more general attackers, who want to fool you into installing Mac apps that appear to be legitimate, but actually encrypt your personal files and hold them for ransom (ransomware). iOS and iPadOS don’t allow this vector because of how apps are installed and files managed. And even after over a decade into what remains rampant use of ransomware, that scourge hasn’t found a foothold on Mac.

From the mid-2020s, I would also argue that governments of democracies have increasingly chosen to enact laws or stretch the limits of existing ones to intrude into our private spaces, including accessing data that they would never previously have considered due to pushback from both ends of the political spectrum and, in some countries, a strong libertarian philosophy on the primacy of privacy.

Even if you don’t believe you fit in a category where the government of the place you reside would target you personally, you should assume your risk is elevated in any country that is sweeping away previous protections in the vague interests of “protecting children” even when no children are involved and “national security” when no national security interests are shown.

The high value of privacy violations

Some unwanted software doesn’t mess up a device or steal data, but installs adware that can display rogue ads (overlaying ones served by webpages), hijack web searches, and redirect affiliate clicks through portals controlled by the operators to make money illegitimately off you from advertisers. Other software is more insidious, tracking your location to sell it to companies that target you with ads—it’s a kind of malware, even if it doesn’t subvert the device.

The most obvious vector is a Mac, where you can install third-party software that isn’t vetted by Apple. But given that you can install extensions in Safari for the iPhone, iPad, or Mac, and that Apple has routinely failed to catch App Store apps that violate user privacy or include adware components, you can be at risk on any platform. Fortunately, so far, I have heard of no iPhone or iPad examples.

To step up protections, you can engage any or all of the following security or software integrity steps that reduce the area of attack on you that could succeed:

  • Two-factor authentication (2FA): This extra step for logging in deters attackers who have phished or otherwise obtained your password. Apple requires 2FA for Apple Accounts (with a few legacy exceptions), limiting access to iCloud-synced information, purchases, email, and much more. Most non-Apple services offer code-based 2FA (sent via SMS) or other ways to validate a password login. To compromise your account, someone has to obtain your SMS messages, your trusted devices, or your authentication app.

Some phishers perform a “two-step” attack in which they convince you not only to enter your account name and password on a site, but then also relay that information in real time to the actual site you intended to access. This causes the real site to send you a confirmation code (or the fake site requests that you generate one). The attackers capture that code when you enter it. However, that scam works only for brief periods, as short as one minute.

  • Passkey: Upgrade accounts at websites that support passkeys, a secure method of logging in that’s deeply embedded on iPhones, iPads, and Macs, and supported by Google and Microsoft. The secret part of a passkey is never transmitted over the internet, and a passkey is phishing-resistant. You can sync and share passkeys when using recent operating systems and password managers. I’ve shifted from tolerating passkeys to preferring them to a password-and-second-factor combo. See where Apple stores your passwords and passkeys.

Sounds great, right? But passkeys are, in every case I’m aware of, a supplemented to two-factor-protected accounts, not a replacement. Until you can make a passkey replace a regular login (with some kind of recovery option), they’re only as secure as the next-weakest link in the chain.

  • Hardware security key: Another form of 2FA, a relative of a passkey, is a hardware security key. These small physical objects plug into a USB or Lightning port or can connect via NFC to iPhones or iPads. The hardware key has embedded encryption circuitry that generates a unique, highly secure login key for each site you use it with. These keys are built on a standard nearly identical to the technology underlying passkeys, and most websites that support passkeys can accept a hardware security key and vice versa. (These keys also rarely fully replace access to an account yet, meaning a flaw in password and two-factor authentication could compromise access.)
  • Apple Pay: Avoid sites that don’t let you pay by Apple Pay, which prevents your credit-card number from being transmitted directly.
  • Install financial apps: Financial apps and their associated notifications make it more likely you will know immediately if any part of your financial life has been manipulated without permission. I’ve noticed a trend since 2024 for financial apps that support Face ID or Touch ID to let you log in from a desktop browser using a QR code or a push notification from the app. You then verify via biometrics, so you’re never entering any credentials in a browser.

Apple already blocks the direct installation of unsigned software on a Mac—apps that were released by people without an Apple Developer account or who bypassed Apple’s minimally involved signing system. By not allowing the easy installation of unsigned software, Apple prevents most malicious software from running at all. See how Gatekeeper decides which Mac apps can run.

  • Continuous backups: The technology for making constant, secure online backups of documents and creating local clones and backups obviates risks more present now than in the past when those options were slow, expensive, or not feasible due to cost or bandwidth limitations. Having such backups in place gives you a point to revert to if you have data corruption or loss.
  • End-to-end encryption (E2EE) for iCloud: Apple’s Advanced Data Protection lets iCloud users put media, notes, reminders, and iCloud Drive files under the gold standard of end-to-end encryption, which requires possession of a device and the means to unlock to access data. Because we may store details that can be used to exploit us in these various kinds of media, E2EE is another leg up on attackers. See how to turn on Advanced Data Protection.

By using Apple and industry technologies and safeguards and keeping backups current, you can dramatically reduce your likelihood of risks while also curtailing the liability that results. Even if you’re infected by ransomware—an unlikely event—and don’t want to pay, you might lose no files by reverting to a snapshot before the attack; or if someone guesses or obtains an account login, you’re alerted as they try to log in, so you can change the password, or they’re blocked entirely without a second factor or hardware element.

The change in our general risk profile over time, however, comes with one big flashing red light. I noted a couple of times above that most people only need to take certain default strong, reasonable measures. However, if you’re someone in particular fields of work or who engages in political advocacy, you may face targeted attacks that evade basic measures that suffice for everyone else.

A human-rights reformer in an incipient dictatorship needs to take more safeguards than a suburban online shopper in Ohio. But identity theft can sometimes lift that Ohioan—or you—into a much higher category of risk, because someone decides your assets or information are valuable to them, and they’ve acquired credentials or personal information that will let them attempt to crack your security shell.

What about children?

If your minor child has their own iPhone, iPad, or Mac, you might assume they are at very low risk. After all, their device probably contains nothing but games, educational software, a school-provided office suite, and a browser playing videos from Disney+.

But no! Sad to say, children are at greater risk than adults, all else being equal, because they’re less experienced and more trusting—and because, let’s face it, there are a lot of creeps out there who stalk children online.

If you travel to a country with severe laws or a propensity to jail people without legitimate charges, you should raise your risk profile before you travel and while there.

If you’re at higher risk, you should consider taking the most stringent measures available. Check the following criteria to see if they apply:

  • You work in the financial, legal, medical, or government sector: If you use Apple hardware for work, you are likely subject to regulatory requirements and have been briefed on them. (You might even have had to take a course on compliance!) You may be required to engage additional security, like using a VPN, blocking ports for USB/Thunderbolt and SD Cards (see the Mac settings worth changing), enabling FileVault on a Mac, and turning on Advanced Data Protection in iCloud. You may also need to enable hardware security keys for your Apple Account. If you don’t take these steps, and it’s discovered, your devices are lost or data intercepted, or online accounts are compromised, you could be sanctioned, fired, fined, or even charged with a crime, depending on the employer and locality.
  • Your device contains unusually sensitive data: This could be old love letters you don’t want your partner to see, confidential business information from your employer (even if they’re not in the financial, legal, etc., categories above), records of a delicate medical condition, or anything else that could cause you serious problems (like loss of your job, insurance, or marriage) if it were to get out.
  • You’re famous: Congratulations! You already know the price of this on social media and when dining, traveling, or walking around, depending on how well-known you are. But you’re also more of a target online, because of the obsession so many sites and people have with secrets about people who are seen to be famous.
  • You’re a journalist: Sadly, reporters are frequently targeted by criminals, people they’re writing about, and governments. For instance, Ronan Farrow reported that Harvey Weinstein hired an Israel-based private-intelligence firm to dig up dirt on him while he was researching his watershed story on Weinstein’s history of alleged and proven sexual crimes.
  • Wealthy in real terms or cryptocurrency: People with more than a little money are regular targets, especially if they have significant Bitcoin or other cryptocurrency holdings. Having an expensive house doesn’t mean much in the current real-estate market; it’s more likely that you have elevated risk if there’s coverage or securities filings that disclose your wealth, stock grants, or other assets.
  • Rough travel: You frequent any of the internet’s seedier neighborhoods, such as sites that traffic in online gambling, porn, or pirated content (like software, television shows, or movies).
  • Secret or pseudonymous identity: You have an online identity, separate from your real-life identity, that you need to keep private. A number of times in recent years, someone whose job or political position has prevented them from having a public persona have been outed for writing under another, typically fictitious name.
  • Heated online interactions: You engage in controversial discussions that might result in people being exceptionally angry with you.
  • Careless co-users (Mac): Specific to a Mac, you share it with less-sophisticated family members who may not be as careful as you would be about downloading files from unknown sites, clicking links in email messages, and using good passwords. While you can set them up with their own macOS accounts—you should!—some of their actions can affect the entire Mac and your online accounts.
  • People in particular professions and of genders other than male: It’s a sad fact of modern life that being a responsible journalist, being an advocate for vulnerable people, believing the Earth is round and evolution legitimately established in the fossil record, or having the temerity to be a gender that someone else has chosen to be angry about online can cause reactionary individuals and groups to target you.
  • You live in a country that has reduced privacy protections: Various countries have fought with Apple over allowing back-door access to iCloud data. The United States asserts the right to login to examine incoming tourists’ and students’ social media and other accounts. Many countries now think that any checkpoint, traffic stop, or other incidental encounter gives them carte blanche to demand all your data.

Now for the good news! A decade ago, my advice to you would have likely been far more extensive and stringent than for the average user. These days, however, Apple’s and other companies’ baseline security is more accessible, easier to use, and more effective.

My general advice is to do everything suggested here as the baseline, and build a bit from there.

Take a hard look at Lockdown Mode

Some people are pinpoint targeted by spyware, software that can hijack their devices, often without a single click, using previously unknown exploits. These attacks are worth a lot of money and thus typically deployed in a targeted fashion by governments and criminal syndicates against journalists, members of minority groups in a given country, human-rights activists, and opposition politicians.

To help counter these kinds of intrusions, Apple offers a Lockdown Mode you can invoke that highly restricts many forms of inbound messages and traffic. For the full rundown, see how to turn on Lockdown Mode and who needs it.

If you fall into the above categories, your biggest risks will come from how your Mac is set up, rather than your iPhone or iPad. Here’s how you could improve your Mac security:

  • Upgrade your Mac to Golden Gate: Golden Gate supports all Apple silicon Macs. A few older Intel models can upgrade to the previous release, macOS 26 Tahoe, which you should do. If you can’t run Tahoe or Golden Gate, you’re not getting the latest and best security. Consider upgrading your Mac if that’s important to you. (See which Macs can run it.)
  • Allow FileVault: Apple enables FileVault by default when you upgrade to macOS 26 or 27 and on new computers running it. Leave it on (see FileVault). Also, power down your Mac whenever it’s not in use; never leave it idle and running for more than a brief period. (A FileVault-like feature is part of iOS/iPadOS and cannot be disabled or configured.)
  • Block device and card insertion: Thunderbolt and USB devices and SD Cards plugged into your Mac can be blocked from interacting with the operating system without authentication. See the Mac settings worth changing.
  • Never make local, unencrypted copies of your data: All local copies should be on encrypted volumes that are unmounted after backup or shutdown when you regularly shut your Mac down; all hosted backups, if any, should only be with firms that offer strong, user-owned encryption. Time Machine lets you set up backups on an encrypted drive or add an encryption key for networked backups. All online backup services worth considering put the encryption key for your archived data solely in your hands.

Apple keeps upping the ante on how it makes sure that macOS’s core files—all the bits and pieces in the operating system that allows apps to run—aren’t messed about with.

What if Apple could prevent system files from being modified at all by placing them on a read-only disk, effectively blocking changes to those files at nearly the lowest level?

That was a hard task, given that system files and user data files co-existed on the same startup volume. But, hmm, wait a tick! What if you could split system files into one volume and data files into another, but have them appear seamless as a single “drive” in macOS? The system volume would be read-only; the data volume could be read/write, but would also have all the sandboxing protections already in place.

That’s exactly what Apple did starting with Catalina. Apple’s modern filesystem, APFS (Apple File System), among other improvements, added the concept of breaking a drive into containers instead of partitions. (Partitions can still be used, but there’s no advantage.)

In the long-used previous filesystem, Mac OS Extended (sometimes called HFS+), a drive was broken into partitions, and each partition could be mounted as a volume. One volume was much like another.

In APFS, a drive is broken into containers, which are like partitions in occupying a preset portion of the disk’s full capacity. Each container can contain one or more volumes, and each volume can have a role. A role defines the kind of data stored on it. Roles include data (for regular mountable data volumes), system (for system files starting in Catalina), and backup (for Time Machine backups starting in Big Sur).

Roles also include obscure and/or invisible system requirements, too: Preboot, Recovery, and VM (virtual memory).

Catalina’s system role also added another variation on containers and volumes, called a volume group. A volume group is two or more interrelated volumes that present as a single entity to the Finder and user. Behind the scenes, however, multiple volumes are managed by the system.

The reason for this was to take a previous system integrity concept to yet another level: all system files are on one volume in the startup volume group; all user data is on another volume.

Big Sur went even further. It doesn’t even mount the system volume. Instead, it uses a “snapshot” feature of APFS that allows the filesystem to capture a particular point in time. Starting in Big Sur, a snapshot of the system volume is loaded that can’t be changed, because it has no writable components—it’s like looking at a picture. In Disk Utility the system is marked as an APFS Startup Snapshot with a unique name, while the main system volume is dimmed.

On top of that, each file on a Big Sur or later system volume has a separate cryptographically generated hash that’s stored in the volume’s metadata. Whenever a file is read from the system volume, that same crypto operation is performed, and the resulting hash of the loaded file checked against the one that’s stored—any modification, however unlikely it could be to occur at all, would be immediately spotted. That’s why this approach is called a Signed System Volume. The metadata and other volume attributes are hashed and collected in something called the seal, which is verified at boot time. If the seal can’t be verified, you’re prompted to reinstall macOS.

Monterey kept the same structure, but added the capability for Apple silicon Macs to install multiple versions of macOS on a single drive. With Big Sur, an Apple silicon Mac could only have a single system because of some low-level decisions about how the Mac decided whether a system could validly start up. With Monterey, you can create additional partitions and install unique copies of macOS into each partition. (From Ventura onward, Apple doesn’t seem to have made substantial changes—or at least I couldn’t find any to report on.)

Only some people need to have multiple versions of macOS on a bootable drive, such as those who need to keep older versions of macOS running for testing or compatibility.

With Apple silicon Macs, Apple also has what’s called hardware-based memory protection. Hackers often use a system or app exploit to overflow an area reserved for pure data into an area that contains executable program code. This lets them insert malicious code that is run in place of legitimate code. Memory protection in Apple silicon processors marks memory areas as either full of executable code or full of data, but not both. In that scenario, a hacker cannot write malicious code into an area that can be executed; nor can they execute code that’s in a place only inert data is stored. An app can change the state of memory areas explicitly, and that’s a place that hackers will certainly aim for. But it’s much higher-hanging fruit.

System integrity and locked apps

Because the system volume is immutable, Apple can place only certain of its apps on that volume: ones that don’t require regular updates. These apps can be refreshed as part of a system update, as a Catalina or later system update has the rights to make changes to the system volume, including those apps.

The list of system-locked apps is reasonably long. You can find them in /System/Applications. A few examples among many are App Store, FaceTime, Mail, Photos, Preview, and Siri.

System volume apps appear within the Applications folder intermingled with Data volume apps. This is part of the seamless integration of volumes in a volume group used for macOS. You can check on the system/Data location of any app by selecting it and choosing File > Get Info. The path shows drive name > System > Applications for system volume apps, and drive name > Applications for ones installed on the Data volume.

Interestingly, Safari is not on the system volume. Apparently, it’s updated regularly enough and sometimes with significant fixes that Apple has kept it out of that fixed side of things.

In a similar but distinct bit of processor-based protection, after macOS loads on a Mac with Apple silicon, the memory its central components occupy—its kernel—is locked using “kernel integrity protection,” so they cannot be modified while macOS is running.

Do you feel safe now? You should to the extent that it’s feasible that Apple has taken every modern and many inventive measures to render the system immutable.

How to restart in recovery mode

Apple installs a special recovery volume as part of a macOS installation that you can restart from to perform actions on your Mac’s system without macOS itself running. This volume is invisible to you in your normal use of macOS.

On an Apple silicon Mac, choose Apple menu > Shut Down. When your Mac has powered down, hold down the power button; you first see a message that says “Continue holding for startup options.” Keep holding until you see the next prompt, which says “Loading startup options.” Click Options, choose an account, click Next, enter its password, and click Continue.

Apple changed the name for this form of boot a few years ago. Recovery mode generically means a special way of booting any Apple device to repair or reinstall its operating system.

When you restart into recovery mode, Apple’s Platform Security Guide says you are booting into recoveryOS. The app that appears first on an Intel Mac or after clicking Options on an Apple silicon Mac is labeled Recovery on the system menu.

Furthermore, if you choose the Utilities menu, you can launch a special Recovery Assistant! The main screen there is labeled not Recovery Assistant, but simply Recovery—see below. If you lock your Mac via Find My and then unlock it, Recovery Assistant launches on restart, and while the app menu reads “Recovery Assistant,” the main title on the screen is “macOS Recovery.”

Startup protections

This wasn’t enough? Really? Really. There’s more. Apple has several methods of further preventing your Mac from being started up in a way you don’t want and to prevent after startup in ways you don’t want.

Share a disk

As part of enhanced protections on Apple silicon Macs, Apple eliminated a simpler option long used on Intel Macs. Follow these steps to share a volume, making it appear as a networked volume on the other Mac:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Share Disk.
  3. Select the disk to share, and click Start Sharing.
  4. If prompted, choose an account, enter its password, click Unlock, and click Start Sharing.
  5. Connect your Mac to another one via a USB data cable (with Type-A or USB-C plugs on either or both ends) or a Thunderbolt 3 or 4 cable.
  6. On the other Mac in the Finder, click the Network link in the sidebar to view the shared Mac’s volume.
  7. Click the Mac in the main window, click Connect As in the upper-right corner, select Guest as the user, and click Connect.

You can now transfer files between the two computers. When you’re finished, eject the mounted Mac volume by selecting it and dragging it to the Eject icon in the Dock or pressing ⌘-E.

Startup Security Utility

Apple took a harder line on startup security policy when they introduced Apple silicon Macs than they previously had with Intel models. macOS offers Full Security, which locks your Mac down to either its current version of macOS or any version Apple currently supports—typically a limited set. Reduced Security lets you run older versions of macOS that Apple previously approved to run on your hardware.

Almost unrelated, the “Allow accessories to connect” option lets you set a boot policy to restrict connections. For options, see the Mac settings worth changing.

Reduced Security lets you select or deselect the option to install signed legacy (or outdated) kernel extensions; and for remote management, which is used in schools and businesses, to control these kernel extensions and software updates. Some organizations may need specific older extensions for security software and may also want to delay automatic software updates to avoid breaking them.

People at a heightened level of risk could trust Reduced Security with just user management enabled for kernel extensions, since those extensions must be signed by “identified developers” (via Apple’s process) and require user steps to install, as described in Manage System Extensions.

If you don’t have Reduced Security enabled and try to install a system extension, the app installation explains what happened.

Proceed to click Open System Settings, and you see a note in System Settings > Privacy & Security.

Click Enable System Extensions and you see a dialog that provides a shortcut and offers abbreviated and somewhat misleading steps on enabling Reduced Security. If you want to proceed, click Shut Down in that dialog and then follow from step 2, below.

Starting from scratch, follow these steps:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Startup Security Utility.

Note: Apple requires an internet connection when you change the security policy, and you can hit a snag if you follow step 2 too quickly. If you see the error “An internet connection is required to change security policy,” quit the app (labeled Startup Disk when launched), wait for the Wi-Fi icon to show a connection in the menu bar, and launch the utility again. (An Ethernet connection doesn’t work.)

  1. The app launches. Click Unlock to mount the disk, which will be encrypted.
  2. Select an administrator user, enter the account’s password, and click Unlock.
  3. Select the drive if it’s not already selected.
  4. Click Security Policy.
  5. Select the level of security you want to apply and click OK.
  6. When prompted, select an administrator user, enter the account password, and click OK.
  7. “Applying security policy” appears. It may take several to tens of seconds to complete.
  8. Quit the utility and choose Apple menu > Restart.

Tip: Reduced Security disables Apple Pay on a Mac with Touch ID capability. See how to set up Touch ID and Face ID.

Permissive Security (not shown in this section) is an additional option that can’t be selected without disabling an even lower-level feature: System Integrity Protection. The Startup Security Utility then adds Permissive Security as an additional radio button. However, it’s not “no security,” but rather “experimental security”: it allows a very particular kind of installation, in which researchers and other niche users create custom kernels—the heart of the operating system—outside of the Apple-signed ecosystem of macOS versions compatible with Apple silicon Macs. It is exceedingly unlikely you would ever need it.

Recovery Assistant

Apple added Recovery Assistant in Tahoe to deal with situations in which macOS couldn’t start up correctly, and some sort of repair was required that needed the startup volume unmounted. If you encounter this, you will see a Recovery screen that explains the issue. You can also launch Recovery Assistant from macOS Recovery by choosing it from the Utilities menu.

The process works like this:

  1. At the Recovery screen, click Continue.
  2. Apple asks if you are willing to send them diagnostic data, and warns you about privacy issues. Click Don’t Send Data to Apple or Send Data to Apple.
  3. Click Start, and the assistant tries to resolve the problem.
  4. The assistant reports one of three states:

1.1. Your Mac was recovered successfully. Click Restart Mac.

1.1. No known issues were found. Click Restart Mac.

1.1. Your Mac could not be recovered. Oh, boy, it’s time to look into backups, consult an independent Apple expert or the Genius Bar at an Apple Store, or call Apple Support.

If you open System Settings > General > Sharing, you’ll notice many resources your Mac can share with other devices on your local network—and, in some cases, beyond.

You can share your screen, files, printers, and internet connection, for example, and you can also enable various types of remote access to your Mac.

All these features can be handy, especially in that they enable multiple Macs in your home or office to talk to each other. You can copy a file from a Mac in the other room, or view what’s on the screen of the Mac upstairs when you’re downstairs.

However, Apple pairs easy local access with easy remote access: if your Mac is reachable from the internet, some services you share locally can be available remotely. Some may require a password, but that could be easily guessable if you haven’t been thinking about internet-based attacks. And just having certain services active, like Remote Login, could allow remote attacks if an exploit turned up in Apple’s system software, before such exploits were known and patched.

This isn’t speculative. Apple regularly patches exploits and bugs in low-level software, like sshd, the secure shell daemon, the system software that handles remote Terminal-style sessions if you have Remote Login enabled. Those flaws are usually fixed before anything terrible is unleashed in the wild, however.

How exposed you are comes first; which sharing services are safe to turn on follows from it.

What’s your risk of internet intrusion?

The most likely determinant of risk to attacks or intrusion via the internet is how directly reachable your Mac is. While the vast majority of routers have a public IP address, very few computers on local networks do. Almost always, your router receives traffic and then re-addresses it to your Mac.

A public IP address is by definition routable or reachable from the rest of the internet. The network of which it’s a part appears in routing tables traded among the devices that exchange data across this mighty global beast.

However, IP addresses can also be static or dynamic. A static address is assigned to a device and doesn’t change over time without typically manual involvement in changing settings. A dynamic address can change at will, and it’s automatic.

Private network addresses can be either static or dynamic; most of us have networks configured to assign the next available address when a computer, phone, or other device requests one. Some routers can be configured to assign static private addresses to specific devices.

If you’re not running a business network or paying extra, your broadband router typically has a dynamic public address. The ISP may rotate the address every once in a while, or if there’s a service outage or you restart the router, a new address is assigned.

The dynamic nature of these public addresses assigned to routers doesn’t aid in security in any fashion, because they’re still public. You might not be trackable by public IP, but your router is still reachable.

A public IP address is simply one that’s uniquely assigned across the internet, and can be reached from anywhere else on the internet. Your router almost certainly has a public IP address, because that’s how it interacts with the rest of the world on your behalf.

It’s a very low bar for any interested party to scan all the originally defined set of public addresses on the internet—yes, as many as hundreds of millions of them—to find open access for services that the scanner might know potential security exploits for, sometimes far out of date…but there are a lot of old, unpatched machines on the internet. Thus, with a public address, there’s no obscurity possible.

That “originally defined” part uses an addressing scheme called IPv4; a newer standard, IPv6, is more resistant to bulk scanning. See the IPv6 section below.

Most homes and businesses rely on private IP addresses for everything but their broadband connection’s router, however. These reserved ranges are only used on local networks, are managed by a router (using something called Network Address Translation or NAT), and typically assigned out automatically with DHCP (less well known as Dynamic Host Configuration Protocol).

Private addresses, which are usually in the form 10.0.1.x or 192.168.1.x, can be reached without any special effort by other devices on the same network of privately assigned addresses. However, when a device on your network makes a request outside its private network range, like viewing a webpage, the router rewrites the request to use the router’s public IP address, and sends it out; the router receives a reply and then forwards it to the locally connected device that requested it.

If you were to have a public IP address on your Mac—not just on your router—it would be like standing on a street corner instead of being inside a house with a locked door and a mail slot. Anyone can come up to and start talking to you or assault and rob you! (Unlike in the world of atoms, where violent crime is minimal and has drastically fallen in recent years, an internet mugger can attack targets wherever they are and a huge number simultaneously.)

The same effect happens if you configure your router to connect its public address with specific services on one or more devices on the local network. For instance, some people want to have a globally available web server or file server, and it’s not terribly hard to expose the correct connection. That makes that web server or file server just as exposed as if the Mac had a public IP address—but only those services, not everything else shared on the Mac.

NAT isn’t designed as a security measure: it’s just a spreadsheet the router maintains to wire requests and replies together. It’s incidentally a general security measure because it makes potentially exploitable open doors on your devices nearly impossible to reach without being specifically targeted, particularly with a router that can be subverted.

You may already be sure you don’t have a public IP address on your Mac: your ISP charges extra for public addresses you use beyond the one attached to your router, and you know you’re not paying for it; your ISP doesn’t offer public addresses; you specifically made sure you weren’t getting one from your ISP; or you’ve configured your router and you know exactly how you set things up.

If you’re not sure, walk through this list:

  • Check your Mac’s address: You can examine the IP address assigned for your active network interfaces. Go to System Settings > Network and select each of your active interfaces in the main pane:

— Ethernet and most interfaces show the address in the main pane under or next to “IP Address.”

— For a Wi-Fi interface, click Details to see the address next to IP Address.

  • Check your router: Connect using the administrative controls for your router, log in, and look at where your router shows its WAN (Wide Area Network), Modem, or Internet IP address, and how network addresses are handed out under DHCP, LAN (Local Area Network), or similar labels. The WAN side is almost always a public IP; the LAN/DHCP part almost always private.

If the IP address of your Mac or LAN/DHCP addresses on the router is in any of these ranges, it’s a private one, where x is any number from 0 to 255: 10.x.x.x, 172.16.x.x to 172.31.x.x, or 192.168.x.x. Otherwise, it’s almost assuredly public.

Type in “what’s my IP” at Google and it will tell you what it thinks your IP address is, and offer a list of sites that do the same (sometimes with more detail). However, if you’re in a DHCP/NAT scenario with private addresses, which is what nearly all home users and most business users are, the address shown on the website is the one associated with either your broadband modem or a further upstream router run by the ISP—not your Mac.

IPv6 adds a wrinkle

Technically, the IP address style x.y.z.a, like 192.168.0.1 or 36.44.0.6, is IPv4 (version four), which has been in use for decades. For nearly 30 years, internet mavens have been trying to migrate the networks that comprise the internet to IPv6, which has a lot of advantages. This includes more addresses that can be assigned, the so-called address space. Where IPv4 has billions of potentially usable addresses, IPv6 has hundreds of undecillions.

However, the trouble has been all the inertia of having billions of devices and hundreds of millions of routers and pieces of plumbing designed around IPv4. While the internet has largely retooled—after nearly 30 years—so that IPv6 works as well as IPv4, nobody wants to end the widespread use of IPv4 in residential networks and many company networks, because of private addressing. IPv6 was designed before NAT became broadly used and thought of as a quasi-security measure to prevent ingress to ISP and corporate networks.

For most of us, that means until private addressing can work in a similar way within IPv6, our ISPs have assigned our routers a public IPv4 address, and have chosen one of several paths with IPv6:

  • Ignored/disabled: Your ISP may simply not pass IPv6 traffic, and it’s not an issue for security.
  • Allow, but disabled by default: You can use IPv6, but you have to configure your router to allow it. My ISP requires a special router for its fiber-optic service, and has detailed instructions for enabling IPv6. Since I have no specific need of it, I’ve left it disabled to reduce my exposure on the public internet.
  • Turned on by default: You may have an ISP, like my editor Dave Johnson, who enables IPv6 by default through its system, and your router and devices all automatically get IPv6 addresses, just as they do IPv4 ones.

If you’re in that last situation, you may have publicly reachable IPv6 addresses—it can be hard to tell, because some ISPs use techniques that are similar to NAT. If the IPv6 addresses are truly publicly accessible, they expose the same general risk of remote attack as public IPv4 addresses and should follow the advice in the next section.

But some analysis suggests it’s not as bad as it might seem. The Internet Society has an interesting FAQ about IPv6 and security, and notes that attackers could find “infrastructure nodes” reasonably easily—the routers that form the backbone of the internet and connect ISPs, streaming services, data centers, and so forth all together.

But, the document explains, “It is generally unfeasible though to address scan a network for client devices, since their addresses are randomized over a very large address space.” Simplified, it means that it’s not a needle in a haystack, but 10,000 needles in a Nebraska-sized area of haystacks. (With IPv4, it’s a cubic foot of hay and you can see all the needles inside.)

If you’re truly concerned, you can disable IPv6, as it isn’t a mandatory or critical part of using the internet. Here are three possibilities, the first two of which will affect your entire network:

  • Disable IPv6 at the router: Find the manual for your router and follow instructions to disable IPv6. It may be as simple as selecting a radio button.
  • Ask your ISP to disable IPv6: Contact your ISP and ask them to disable IPv6 on your account or router if they control your router or have the ability to do this at a higher network level.
  • Disable IPv6 on your Mac: If you can’t or don’t want to disable IPv6 network-wide, disable IPv6 on your Mac. Go to System Settings > Network, select an interface, and click Details. Select TCP/IP and choose Link-Local Only from the Configure IPv6 pop-up menu. Click OK. This leaves other devices still reachable via IPv6, but at least locks down your Mac.

You can’t disable IPv6 on an iPhone or iPad.

If you lose your macbook you may want to locked it in find my to make sure no one would take it. When you find it, you may want to unlocked it. You can put in your passcode as normal and unlocked it. This may only allow you to use it as normal for a few minutes then it would suddenly go black and showed a lock. Whenen this happened, you won’t see any writing on the screen and entering your password won’t do anything. If you locked your macbook through find my and can’t unlock it now, here’s what you can do.

To unlock any Apple silicon Mac or an Intel Mac with a T2 Security Chip (models released starting in 2018), follow these steps:

You could be stuck if you’re using a Mac with multiple accounts that another account holder has Find My control over and that person locks it. You need them to perform the unlock in person or read you their passwords. This could be awkward.

  1. After marking the Mac as lost, it appears with a question mark overlaid in the Devices view.
  2. When the Mac restarts, it shows the macOS Recovery screen with Recovery Assistant appearing as the active app in the upper-left corner.
    • Apple claims the message you entered will appear at startup. It does not, in my testing.
  3. The account used to lock the Mac is the only one that appears. Click its icon and click Next. Only one account appears because only one account per Mac can be used for Find My.
  4. Enter the account’s password and click Continue. If you don’t remember your password or it doesn’t work, you can click the “Forgot all passwords?” link, which takes you to the FileVault Recovery process. Using that method, you can enter your Recovery Key, reset the password, then restart step 2.
  5. If you entered it correctly, “Authenticated succeeded” appears. Click Restart.
  6. The Mac restarts again into Recovery Assistant. This time the screen reads Activate Mac.
    • You reconnect with your Apple Account by entering its password.
    • You can select any macOS account that can log in to the Mac, provided you know the Apple Account shown next and its password.
    • Select the account, enter its macOS password, and click Next.
  7. You may be prompted to enter your full Apple Account email address; a Mac shows you a portion of it. Enter it and click Next.
    • Your Mac prompts you to enter the password associated with the partially displayed Apple Account address, or the one you just entered in full.
    • If you don’t have that password, click the link below the field, Use Device Password, and enter the last password used to unlock the Mac in a regular session before it was locked. In beta testing, I found I didn’t get a field to enter that password in, but this may have been fixed by the production release.
  8. On a successful entry, the Mac restarts yet again after a one-minute countdown. Enter your password when prompted to start up into a regular session. Apple Pay will have been disabled, and your iCloud sync is probably paused as well. When prompted, enter your Apple Account password (or passwords if you have multiple accounts linked to your macOS account).

The first time I tried this with macOS 27, I had to choose Apple menu > Restart after it wouldn’t proceed. Then I followed steps 5 and 6 above again, and it worked.

If your Apple Account gets locked

If you try this too often, as I did while testing, or for other security reasons only Apple knows, your Apple Account may be locked. At step 6, I was told I had to reset my Apple Account password from one of my other devices; all four of which are linked to the account were shown. I made that change. In one of the public beta versions, clicking Unlock Account did nothing before or after changing. I was able to click Cancel, complete step 6 again with the new Apple Account password, and proceed to step 7 and restart.

The alert’s title reads Update Phone Number, even though there is no opportunity to do so. This may be fixed by Apple later, though I doubt it.

Apple’s email is out of date

The process above was documented using macOS 27, and Apple has made slight tweaks and major improvements over the last few years. However, the company appears unable to shake off the vestiges of the past. Years ago, when you locked your Mac, you had to set a passcode to unlock it. While that isn’t supported with Apple silicon Macs or Intel Macs with the T2 Security Chip, the email Apple sends out still shows a thumbnail screen where you would enter that code and tells you that you can only unlock your Mac with that non-existent passcode.

Tags: Find My, macOS

Malware describes a broad category of unwanted software that is installed without your explicit knowledge, and which carries out tasks beneficial to the operator and creator of the malware, and detrimental to you, your local network, your friends, family, and colleagues, and potentially strangers and even the whole of the internet.

Malicious software can be as “benign” as adware, which is bundled with software you intended to install, and which redirects your browser to a portal through which the adware’s creator earns commissions when you search or make purchases; or which overlays or replaces ads on pages you view to earn income on your stolen time (also effectively stolen from the sites you visit).

But it can also be quite hostile: it might encrypt all your files and demand a ransom (more on that below), delete your files, or use your computer to launch attacks. Malware often tries to find other devices reachable on the same network—often which are more susceptible to network infiltration than from attacks launched over the internet—to infect them with the same software.

The main point is that you don’t want any software to run on your Mac that you aren’t aware of and haven’t given approval to run. What follows is the kinds of threat a Mac user faces; what Apple does about them and what you can do is separate, as is whether to install anti-malware software at all.

Why Apple avoids the worst of it

While the first widespread malware appeared on Macintoshes many, many years ago, Apple’s choices over the last 25 years have meant that Macs have been generally resistant to the most common vectors of attack that afflicted and still plague Android and Windows users, as well as people running servers of all types.

There are a lot of reasons for this, some of it due to system choices and some due to obscurity—the number of devices running each operating system.

Windows wasn’t designed with the internet in mind, nor the receipt of arbitrary emails from people outside an organization. For too many years, a successful exploit could hijack a machine by someone merely receiving (not even viewing) an email message or passively viewing a webpage. Microsoft has improved its security dramatically in Windows 10, the first release of which was 2015, but older versions—still in use on hundreds of millions of devices—still suffer from many attacks.

While Google built Android as a modern, Unix-based, internet-connected operating system, they made multiple interconnected errors that led to Android being highly insecure. Among other issues, they handed control to handset makers and carrier networks, making it difficult to push out security updates directly. They also rapidly revised and abandoned older versions, no longer releasing security updates, even while handsets were still being sold as new in the box that ran those versions. And despite the dangerous world into which Android was first launched in 2009, the OS seemed full of easily exploitable flaws that took years to move past. As with Windows, even if newer versions of Android are fairly secure (in relative terms), a billion older Android devices still remain on the market.

It’s in this space that Apple finds itself, with both iOS/iPadOS and macOS. Frankly, there are billions of better targets than any of those Apple operating systems. Apple didn’t have to engineer a system that was 10 times better than Windows, but just enough—better coupled with the substantially fewer numbers of Macs in use in the world—that malware creators targeted the low-hanging fruit instead.

While Apple has sold a lot of iPhones and iPads (and some iPod touches), the user base for Android and forked-Android phones and tablets (forked ones use open-source-derived variants) outweighs iOS and iPadOS copies by a bit under three to one—and Apple patches security flaws quickly. (Apple has closed that gap in recent years, but it’s the mass of older devices that remains the concern.)

Remember the old joke about a bear rushing toward two campers woken from slumber: one stops to put on his shoes. The other says, “You can’t outrun the bear!” The first replies, “I only have to outrun you.” Apple always ties their shoes.

The kinds of malware

Malware and its enablers come in a lot of varieties, and it’s worth knowing the terminology. Here’s a primer:

  • Virus: Malware that injects itself inside existing software, and executes whenever that software runs. It can spread by software being copied, such as an app being corrupted by a virus on a download site, so everyone who downloads it receives and runs an infected version. A virus can be a payload of a worm or Trojan horse, which install the virus.
  • Worm: Worms are free-standing malware that can spread themselves across a network, and may install other malware, such as viruses. The world’s first widespread malware was a worm.
  • Trojan horse: Malware masquerading as legitimate or desirable software that a user installs. It may result in freestanding malignant software or a virus inserted into otherwise valid software.
  • Phishing: A technique of convincing someone, typically via email, to hand over personal details, particularly payment information, by sending them to a malicious webpage that’s a close copy of a credible site.
  • Ransomware: Malware that targets user document files and encrypts them with a key that is discarded and only the attacker has access to. The attacker demands money to provide the key.
  • Bots: A bot is not a “robot,” but automated software that performs automated activity on behalf of its owner, which can include coordinated attacks against websites or servers, illegitimately clicking ads, sending spam email.

The most likely scenario for a Mac user to be infected by malware is through a series of seemingly innocent, chained actions: phishing, Trojan horse, virus, and ransomware. Often this has to be coupled with a form of understandable naïveté: bypassing Apple’s warnings and installing seemingly unknown software.

How an infection actually happens

Because I don’t want you to feel targeted in this story, let’s call the victim Bob. Bob is checking his email in Apple Mail or a third-party email app. Because Apple Mail has always been quite resistant to in-mailer attacks and most other mail clients are the same, Bob’s not at risk by reading messages.

But Bob sees a message about a piece of software he uses regularly. “Get a free 90-day trial of the new version of AliceDrawPlus! Click this link, and download and install. Because this is a special trial version, right-click the installer and click Open to make sure it runs!” (Real phishing email is often not that grammatically correct or well targeted, but some is.)

Bob isn’t thinking about unsigned software. Instead, he looks carefully at the email, which absolutely looks like other messages he’s received from Alice Corp. He downloads the file, bypasses Gatekeeper protections, and the Trojan horse he was phished to download runs and installs a virus.

Lest you think this is a problem I know about only secondhand, several years ago, one of my kids was having problems with their computer. I checked, and they had been fooled into installing an Adobe Flash “updater.” I had accidentally enabled administrator privileges on their account, and I had apparently never had the malware talk with them. We installed some anti-malware software, and fortunately the thing they’d installed was fairly benign.

But because the installer is running in Bob’s home folder, and not accessing or trying to install in a privileged location or make similar changes, it doesn’t trigger a request for an administrator password—although Bob might have entered that without worrying, too.

The software appears to install, but instead of launching, it claims there was a license problem, and the file was corrupted. “Check back in four weeks for another update!”

Meanwhile, as Bob continues to work, every file in his home folder, starting with Documents, is being encrypted and copied to a new file and then the original deleted. He may have no notion it’s happening, particularly if he has an SSD and can’t hear a hard drive working away like mad, though his fan might spin up unexpectedly.

macOS requires users to agree to allow apps access to certain folder locations, but because we have been trained to click OK most of the time, it might not raise Bob’s hackles or most of ours. See how to control which apps use your Mac camera and files.

A few hours pass and Bob tries to open a file. It has a strange extension. It won’t open in the app that created it, but when he double-clicks the file, he gets a message that explains all his files are encrypted, he needs to pay up, or the decryption key will be thrown away and his files lost forever.

Bob’s been attacked by ransomware, and his only way out may come if he has a backup history—or wants to pay the Bitcoin or other cryptocurrency the criminal demands.

If Bob were as credulous as depicted, he could just as easily have been phished, where he was presented with a website that absolutely looked like AliceCorp and told to enter his serial number and payment details for a huge discount. Phishing is a virus of the mind, and your Mac can’t help much against that.

ClickFix, the fake CAPTCHA

Bob is too clever to fall for the above, but he visits a website that flashes up a CAPTCHA, which is typically some text you are using your human eyeballs to perform OCR on or identify squares containing the same object (they are stealing our brain’s processing power here), or to solve a simple puzzle. Bob performs the sequence of actions he’s told to perform in the “CAPTCHA,” and he falls to phishing.

This technique, ClickFix, has been around since 2024, but apparently dramatically accelerated how often malware fighters detect it.

Why? Fiendishly simple. We’re so used to following the “orders” of a CAPTCHA, clicking images or solving puzzles, that this doesn’t seem that weird if we’re on autopilot.

However, it should go without saying—but I’ll say it—never paste anything into Terminal from a random source on the internet, whether it appears to have authority or not. I try to avoid it even here, because of the consequences of a Terminal-based command going wrong and taking a lot of your time to reverse.

Apple agrees, and rolled out an anti-paste warning in Terminal! Starting in Tahoe, if you have something on the clipboard that macOS deems could be harmful, you receive a warning that might cause you to think twice.

Apple can escalate further than a warning, blocking paste entirely if they’re sure there’s malware involved. Your Mac may also block a script from running for the same reason.

Ransomware is your biggest worry

While our theoretical friend Bob was fooled into installing malicious software and bypassing protections in the examples above, the risk to many people isn’t quite as straightforward as the above.

Before I dig in, I want to note that ransomware is your biggest worry, but ransomware remains nearly non-existent on Macs as Apple continues to crank up protections that make it increasingly unlikely to thrive—particularly while it’s easy to infect users of other platforms. Several of those are covered in how Gatekeeper decides which Mac apps can run and how macOS protects its own system files.

The reason I characterize it as the biggest worry is that it’s so blessedly simple to create and provides easy rewards for those who deploy it. Macs aren’t inherently resistant to it, but it feels as if they were. That luck could change with the right (“wrong,” really) exploit and timing.

You can see how with a phishing attempt like the above or email messages that tell someone a sequence of commands to perform, ransomware could be rolled out en masse to millions of people. Payments are quasi-anonymous to avoid easy tracking, and ransomware is effective against naïve and some more experienced users because it doesn’t seem like the way in which malware gets delivered and runs.

As noted above, when a ransomware app is launched, it encrypts all user files. The operation typically passes a file through an encryption algorithm, writes a new file with a new extension, and then deletes the source file.

Depending on the attack, you may get a message on screen when it’s done, explaining what happened. Some ransomware embeds the message into every file, so double-clicking provides the same text.

Send hundreds to thousands of dollars (or, as an organization, up to tens of millions of dollars) in Bitcoin to a specified address—kind of like a semi-anonymous post-office box—by the specified date and the hijacker will give you the key to decrypt it. Fail to comply, and they throw away the key.

Occasionally, white-hat hackers, who use their coding and online prowess for good, will crack open a ransomware scam and distribute passwords or a generic decrypting tool to victims!

Ransomware works on the portion of macOS (and any afflicted operating system) that contains user files and for which file and folder permissions more or less all belong to the logged-in user, as well as the partitioned-off part of memory that runs programs, called user space.

This is distinct from the system files and kernel space that contains all the components of macOS and in which the operating system itself runs. While crackers want to subvert system files and have software run with the highest permissions, that’s a hard lift—and why bother, when you can just use ransomware instead?

Here’s the other thing that should reduce your blood pressure if I just raised it: it’s also remarkably easy to mitigate the effects of ransomware (or any malware) with a little prep and ongoing work that’s not likely to exhaust your patience or wallet. The built-in measures come first, and then the question of third-party anti-malware software.

macOS 27 Golden Gate runs on all currently shipping Macs, as well as most models introduced within the past five years or so. Sadly, macOS 27 does drop support for some Mac models that were able to run macOS 26 Tahoe.

Model support

macOS 27 supports all and only Macs with Apple silicon. The full list of supported models is:

  • MacBook Neo
  • MacBook Air (Apple silicon, 2020 or newer)
  • MacBook Pro (Apple silicon, 2020 or newer)
  • iMac (2021 or newer)
  • Mac mini (2020 or newer)
  • Mac Studio
  • Mac Pro (2023)

Unfortunately, that excludes the last Intel-based models that were able to run Tahoe but can now go no further: iMac (2020), MacBook Air (Retina, 13-inch, 2020), MacBook Pro (16-inch, 2019; 13-inch, 2020), and Mac Pro (2019).

To confirm which Mac model you have, choose Apple menu > About This Mac. The panel looks different in Monterey or earlier.

If your Mac doesn’t have an Apple M-series or A-series processor, I’m very sorry to say it won’t run macOS 27, regardless of its age or speed.

Even if your Mac is on that list, however, a couple of macOS 27 features may not work because they have more stringent processor requirements. For instance, improved Dictation accuracy and customizing Siri’s expressivity (Apple’s term) and pace require a Mac with an M3 processor or newer and at least 12 GB of RAM.

New Macs that shipped after macOS 27 was released have it preinstalled. If necessary, you can use Migration Assistant to transfer files, accounts, and settings from your old Mac, and there are some additional steps to complete afterward.

Free disk space

The amount of free space macOS 27 requires for installation depends on a number of variables, including which version of macOS you’re upgrading from and which upgrade method you use. I suggest starting with at least 50 GB of free space before downloading the installer, which itself occupies up to about 21 GB. Some macOS 27 features will require increasing amounts of disk space as you use them, so it never hurts to have room to grow.

To find out how much free space a volume has, select the volume’s icon in the Finder and choose File > Get Info. The window that appears lists (among other things) the volume’s Capacity (total), Available (free), and Used space. Those values can sometimes be misleading.

Once you know your Mac qualifies, the next step is preparing it for the upgrade.

The marquee feature of macOS 27 Golden Gate is the long-promised and long-delayed Siri, now called Siri AI.

Unlike the original Siri, the new version—first promised for macOS 15 Sequoia in 2024—has conversational capabilities similar to other modern digital assistants like Alexa and Google Assistant, plus hooks into many parts of macOS and individual apps. It can function as a chatbot in the same vein as ChatGPT or Claude, and can incorporate information from the public web into its responses.

In short, Siri AI is now (close to) what it should have been many years ago, and reasonably on par with its competitors. It’s far more useful, and easier to work with, than any previous version of Siri. Unlike existing chatbots, Siri AI can access your private data—like email, photos, local files, and calendar events—to provide background information for answering questions. Even better, it doesn’t upload your data—Apple says private data doesn’t leave your device—or use it to teach their AI models.

Meanwhile, Apple Intelligence, a collection of features across Apple devices that incorporate Apple’s take on artificial intelligence, has expanded, and the lines between what’s now considered part of Siri and what’s considered part of Apple Intelligence have blurred. Apple appears to be leaning more heavily on the Siri branding for certain features that were previously called Apple Intelligence. In any case, it’s all of a piece now: enabling or disabling Siri (in System Settings > Siri) also enables or disables most of the other Apple Intelligence features.

Siri AI initially operates only in English, and a few features require an M3 or later Mac with at least 12 GB of RAM.

What follows is what is new with Siri AI and Apple Intelligence for macOS 27 users.

  • Siri works more like a chatbot now: Activities that previously required an AI chatbot like ChatGPT or Claude, or a smart speaker-based system like Alexa or Google Assistant, can now be handled directly by Siri. You can have more natural and extensive back-and-forth conversations, with Siri being more aware of the context of what you’re asking than it did previously. You can drill down on responses or ask it to refine its results.
  • Siri can access the web: As you may have inferred from that example, Siri was using information that wasn’t on my Mac or on Apple’s servers, but rather, “out there” on the web. So, you can ask about nearly any topic, and instead of merely being shown a list of potentially helpful webpages as in the past, now you get the information directly.
  • Spotlight and Siri share an interface: In macOS 27, when you press the Spotlight shortcut (⌘-Space by default), you get a text field that serves both purposes (see Spotlight); the gray text in the field even reads Search or Ask. You can type the name of an app or file, and it will give you the same results as Spotlight always has. But you can also ask questions that Siri will answer from its nearly unlimited storehouse of information. Or you can use a plain-language description of what you’re looking for on your Mac and Siri will find it.
  • Siri knows more about you: Siri can now understand what Apple calls “personal context,” which is to say, information that can be pulled from the various apps on your Mac—Calendar, Contacts, Mail, Messages, Notes, Photos, Reminders, and so on. That means Siri can incorporate information found in any of those apps into its responses and actions.
  • Visual Intelligence comes to macOS: Visual Intelligence was first introduced in iOS and iPadOS, letting your device describe what it saw in a screenshot or the Camera app—or act on it, like extracting information from a poster or a bill. Now your Mac has it, too. This means you can ask Siri about anything on your screen, or have it do something with information on screen. To use this feature, you can simply invoke Siri (for example, by pressing ⌘-Space) and ask a question about something you see on your screen. Or, you can use a new screenshot mode that doesn’t automatically save screenshots. Press ⌘-Shift-6 and highlight a portion of your screen to ask Siri about something in that specific area, or press ⌘-Shift-Space to ask Siri about the frontmost window. Even if you don’t ask Siri anything, it may automatically identify plants, animals, and other elements found in screenshots. (macOS doesn’t yet apply Visual Intelligence to the FaceTime camera or Continuity camera.)

A new switch in System Settings > Siri, Automatic Visual Look Up, is labeled “Identify objects and places that appear in screenshots.” However, I’m unsure what effect this is intended to have, as I am seeing Visual Intelligence hints in screenshots whether or not this switch is turned on.

  • The Siri app is new: There has always been an app on your Mac called Siri, but opening it did nothing more than display the Siri field for you to enter a request. Now, however, the Siri app shows you your previous conversations, and even lets you continue them. Siri conversations sync across your devices using iCloud.
  • More actions are available: Siri could already take certain actions, such as changing your Mac’s volume or turning VoiceOver on or off. In macOS 27, thanks to an underlying framework called App Intents, Siri can take a much wider set of actions in a larger number of apps. For example, you could ask Siri to send a message in Messages containing the title of the song now playing in Music. Most of Apple’s apps already support actions like these, and third-party apps are getting there.
  • You can customize Siri’s voice even more: In System Settings > Siri, click Voice, and you can select a base voice and then drag the Pace and Expressivity sliders as sample responses are played to dial in exactly the tone you prefer.

This feature requires an M3 or later processor and at least 12 GB of RAM.

  • Writing Tools look different: If you select text you want to adjust using Apple Intelligence, you no longer see a Writing Tools submenu on the Edit menu or a Writing Tools badge, but rather a Siri badge in most apps, which you can click to reveal the existing tools arranged differently and without the “Writing Tools” label. Some apps give you access to the same tools via a Siri toolbar button.

Apple Intelligence features are currently available in Chinese (Simplified), Chinese (Traditional), Danish, Dutch, English, French, German, Italian, Japanese, Korean, Norwegian, Portuguese, Spanish, Swedish, Turkish, and Vietnamese.

Now that you’ve gone through all the preliminary steps, it’s time to begin the upgrade to macOS 27 Golden Gate. For most people, Plan A—essentially letting the installer do what it wants—is the logical choice. And remember, if it doesn’t work out for any reason, you can always move on later to Plan B, a clean install. Nevertheless, because you may encounter some questions or confusion during the process, I detail exactly what steps to take from start to finish.

Start the installer

Before you run the installer, if you haven’t already done so:

  • If you are installing onto a laptop, connect its AC adapter to a power source. (If you forget to do this, the installer will prompt you.)
  • Quit all open apps. (The installer attempts to do this for you—and prompts you if it can’t—but you might as well take care of this beforehand.)

To begin the process, double-click the Install macOS Golden Gate icon in your /Applications folder or wherever else you put it. A window appears with just one button: Continue. Click it!

As a reminder, if you chose to use Software Update, there’s no separate installer to run or destination to select.

The Software License Agreement appears next; click Agree, and then click Agree again in the confirmation dialog to proceed.

Select a destination

The next screen—assuming you are using the standalone installer and not Software Update—asks you to confirm which volume you want to install macOS 27 onto. In most cases, it displays its best guess—typically your startup volume—but you may see multiple disks here, in which case you should select the one you want. If the volume where you want to install macOS 27 isn’t visible, you should see a Show All Disks button; click that to display all available options and then make your selection.

If the installer can’t use a volume as the destination for any reason, that volume is dimmed; click it for an explanation. If the volume is empty or contains a recent version of macOS, it should be OK; if not, the instructions may tell you to back it up and erase it. (In some cases you may be prompted to reformat it.)

If you see an “Unsupported partition structure” error message, see what to do when the volume can’t be selected.

With your desired destination volume selected, click Continue or Install (the wording varies depending on your setup). Next, you’re prompted to enter your administrator credentials (in order to add a helper app); do so and click OK (or, in some cases, Unlock).

The installer begins copying files. The copy process typically takes several minutes, but when it finishes, the installer tells you that it will restart your computer automatically in 30 seconds; you can also click Restart to skip the wait. If any apps are still open and the installer is unable to close them automatically (for example, if there are unsaved changes you must respond to), the installer displays a prompt asking you to click Close Other Applications.

Take a meditation break

Depending on a number of variables, including the speed of your Mac and the size of your disk, installation may take less than a half hour or as long as several hours. Apart from the steps you’ve already performed, the process normally requires no intervention until the very end. Until then, you won’t be able to use your Mac for anything else, so now’s a good time to take a break to do some meditation, tai chi, qigong, or yoga—you have a bit of time to kill.

If you insist on watching the installer’s progress bar gradually make its way across the screen, beware: its time estimates (“About 43 minutes,” “Less than a minute,” etc.) are notoriously inaccurate, especially near the beginning and end of the process. And remember: a watched installer never boils.

As the installer progresses, your Mac will restart one or more times, and it may make some unusual sounds (like a long beep). You may also hear your Mac’s startup chime—perhaps even more than once. At the end of the installation, you’ll continue with several additional configuration steps.

When it finishes, Setup Assistant takes over.

The most controversial change in macOS 26 Tahoe, was the new Liquid Glass interface, which greatly increased the use of transparency and glass-like distortion effects that added some glitz to the screen without increasing usability. In many cases, the new appearance made text harder to read, icons more difficult to decipher, and windows more cumbersome to use.

Over subsequent Tahoe releases, Apple made some adjustments to Tahoe to address a few of the most frequent Liquid Glass criticisms. But in macOS 27 Golden Gate, Apple has gone further still, tacitly acknowledging that Liquid Glass went too far the first time around while retaining the overall look and feel introduced in Tahoe.

If you hated Liquid Glass in Tahoe, you’ll probably find it less objectionable in macOS 27, but make no mistake: the user interface looks far more like that of Tahoe than that of Sequoia.

The Liquid Glass slider

In the WWDC keynote introducing macOS 27 Golden Gate, Apple made a big deal about a new slider that ostensibly lets you decide how weak or strong the Liquid Glass transparency effects should be; it appears during installation and can also be adjusted at any time in System Settings > Appearance.

But, in fact, that’s not quite what it does. It merely changes the level of tinting for a handful of interface elements—particularly menus, Control Center, Notification Center, Spotlight, toolbars, and sidebars—that become a bit more or less transparent based on where the slider is set. Instead of having just two choices (Clear or Tinted), as in Tahoe, you can now select any point in the range between the two. But the effect is subtle, and the slider doesn’t change the transparency of the menu bar, Dock, Finder icons, or most other items.

If you want to get rid of most transparency altogether, you must still go to System Settings > Accessibility > Display and turn on “Reduce transparency.” That makes the menu bar, menus, sidebars, and toolbars opaque, while greatly reducing the transparency of the Dock and certain other elements. However, paradoxically, it also removes the shading from sidebars, making them less clearly separated from the rest of the window.

Sidebar improvements

In Tahoe, window sidebars were inset from the window edges, reducing the amount of usable window space. In macOS 27, sidebars once again reach the edge of the window. In addition, macOS 27 brings color back to certain sidebar icons, all of which were uniformly dark gray in Tahoe.

Window improvements

macOS 27 makes two overall changes to windows: showing the active window more prominently and adjusting the corner radius.

In Tahoe, it could be difficult to figure out which window on screen was active. macOS 27 adds cues to make that more evident: the sidebar’s color is darkened, and color icons appear only in the frontmost window.

Another small detail that irritated a lot of people was that Tahoe made window corners much rounder (supposedly to match the curvature of laptop screen corners), which—like the inset sidebars—reduced the amount of usable space in windows. But not all windows got this treatment, meaning some windows had much rounder corners than others, which looked awkward. In macOS 27, all window corners have the same amount of roundness.

Fewer menu icons

Tahoe added icons next to most menu commands, a change with no evident utility (and against Apple’s long-standing human interface guidelines) that made menus more cluttered and inconsistent in indentation. In macOS 27, those superfluous icons are gone, though icons that existed pre-Tahoe are still there.

Updated app icons

Tahoe enforced the rounded-rectangle (or “squircle”) shape for all app icons from Apple and apps downloaded from the App Store. (Apps distributed outside the App Store could optionally work around this requirement.) In addition, Apple’s icons adopted a new look and feel that, unfortunately, also made them less distinctive. The icons haven’t changed dramatically in macOS 27, but they have become crisper and slightly more saturated.

The same slider exists on iPhone and iPad, where it works the same way but changes less; that is covered in how to reduce Liquid Glass transparency in iOS 27.