How macOS Protects Its Own System Files From Malware

The macOS you are running is a read-only snapshot, not the volume itself.

Moses Johnson
By Moses Johnson - Senior Staff Writer, Help & How To
9 Min Read

Apple keeps upping the ante on how it makes sure that macOS’s core files—all the bits and pieces in the operating system that allows apps to run—aren’t messed about with.

What if Apple could prevent system files from being modified at all by placing them on a read-only disk, effectively blocking changes to those files at nearly the lowest level?

That was a hard task, given that system files and user data files co-existed on the same startup volume. But, hmm, wait a tick! What if you could split system files into one volume and data files into another, but have them appear seamless as a single “drive” in macOS? The system volume would be read-only; the data volume could be read/write, but would also have all the sandboxing protections already in place.

That’s exactly what Apple did starting with Catalina. Apple’s modern filesystem, APFS (Apple File System), among other improvements, added the concept of breaking a drive into containers instead of partitions. (Partitions can still be used, but there’s no advantage.)

In the long-used previous filesystem, Mac OS Extended (sometimes called HFS+), a drive was broken into partitions, and each partition could be mounted as a volume. One volume was much like another.

In APFS, a drive is broken into containers, which are like partitions in occupying a preset portion of the disk’s full capacity. Each container can contain one or more volumes, and each volume can have a role. A role defines the kind of data stored on it. Roles include data (for regular mountable data volumes), system (for system files starting in Catalina), and backup (for Time Machine backups starting in Big Sur).

Roles also include obscure and/or invisible system requirements, too: Preboot, Recovery, and VM (virtual memory).

Catalina’s system role also added another variation on containers and volumes, called a volume group. A volume group is two or more interrelated volumes that present as a single entity to the Finder and user. Behind the scenes, however, multiple volumes are managed by the system.

The reason for this was to take a previous system integrity concept to yet another level: all system files are on one volume in the startup volume group; all user data is on another volume.

Big Sur went even further. It doesn’t even mount the system volume. Instead, it uses a “snapshot” feature of APFS that allows the filesystem to capture a particular point in time. Starting in Big Sur, a snapshot of the system volume is loaded that can’t be changed, because it has no writable components—it’s like looking at a picture. In Disk Utility the system is marked as an APFS Startup Snapshot with a unique name, while the main system volume is dimmed.

On top of that, each file on a Big Sur or later system volume has a separate cryptographically generated hash that’s stored in the volume’s metadata. Whenever a file is read from the system volume, that same crypto operation is performed, and the resulting hash of the loaded file checked against the one that’s stored—any modification, however unlikely it could be to occur at all, would be immediately spotted. That’s why this approach is called a Signed System Volume. The metadata and other volume attributes are hashed and collected in something called the seal, which is verified at boot time. If the seal can’t be verified, you’re prompted to reinstall macOS.

Monterey kept the same structure, but added the capability for Apple silicon Macs to install multiple versions of macOS on a single drive. With Big Sur, an Apple silicon Mac could only have a single system because of some low-level decisions about how the Mac decided whether a system could validly start up. With Monterey, you can create additional partitions and install unique copies of macOS into each partition. (From Ventura onward, Apple doesn’t seem to have made substantial changes—or at least I couldn’t find any to report on.)

Only some people need to have multiple versions of macOS on a bootable drive, such as those who need to keep older versions of macOS running for testing or compatibility.

With Apple silicon Macs, Apple also has what’s called hardware-based memory protection. Hackers often use a system or app exploit to overflow an area reserved for pure data into an area that contains executable program code. This lets them insert malicious code that is run in place of legitimate code. Memory protection in Apple silicon processors marks memory areas as either full of executable code or full of data, but not both. In that scenario, a hacker cannot write malicious code into an area that can be executed; nor can they execute code that’s in a place only inert data is stored. An app can change the state of memory areas explicitly, and that’s a place that hackers will certainly aim for. But it’s much higher-hanging fruit.

System integrity and locked apps

Because the system volume is immutable, Apple can place only certain of its apps on that volume: ones that don’t require regular updates. These apps can be refreshed as part of a system update, as a Catalina or later system update has the rights to make changes to the system volume, including those apps.

The list of system-locked apps is reasonably long. You can find them in /System/Applications. A few examples among many are App Store, FaceTime, Mail, Photos, Preview, and Siri.

System volume apps appear within the Applications folder intermingled with Data volume apps. This is part of the seamless integration of volumes in a volume group used for macOS. You can check on the system/Data location of any app by selecting it and choosing File > Get Info. The path shows drive name > System > Applications for system volume apps, and drive name > Applications for ones installed on the Data volume.

Interestingly, Safari is not on the system volume. Apparently, it’s updated regularly enough and sometimes with significant fixes that Apple has kept it out of that fixed side of things.

In a similar but distinct bit of processor-based protection, after macOS loads on a Mac with Apple silicon, the memory its central components occupy—its kernel—is locked using “kernel integrity protection,” so they cannot be modified while macOS is running.

Do you feel safe now? You should to the extent that it’s feasible that Apple has taken every modern and many inventive measures to render the system immutable.

How to restart in recovery mode

Apple installs a special recovery volume as part of a macOS installation that you can restart from to perform actions on your Mac’s system without macOS itself running. This volume is invisible to you in your normal use of macOS.

On an Apple silicon Mac, choose Apple menu > Shut Down. When your Mac has powered down, hold down the power button; you first see a message that says “Continue holding for startup options.” Keep holding until you see the next prompt, which says “Loading startup options.” Click Options, choose an account, click Next, enter its password, and click Continue.

Apple changed the name for this form of boot a few years ago. Recovery mode generically means a special way of booting any Apple device to repair or reinstall its operating system.

When you restart into recovery mode, Apple’s Platform Security Guide says you are booting into recoveryOS. The app that appears first on an Intel Mac or after clicking Options on an Apple silicon Mac is labeled Recovery on the system menu.

Furthermore, if you choose the Utilities menu, you can launch a special Recovery Assistant! The main screen there is labeled not Recovery Assistant, but simply Recovery—see below. If you lock your Mac via Find My and then unlock it, Recovery Assistant launches on restart, and while the app menu reads “Recovery Assistant,” the main title on the screen is “macOS Recovery.”

Startup protections

This wasn’t enough? Really? Really. There’s more. Apple has several methods of further preventing your Mac from being started up in a way you don’t want and to prevent after startup in ways you don’t want.

Share a disk

As part of enhanced protections on Apple silicon Macs, Apple eliminated a simpler option long used on Intel Macs. Follow these steps to share a volume, making it appear as a networked volume on the other Mac:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Share Disk.
  3. Select the disk to share, and click Start Sharing.
  4. If prompted, choose an account, enter its password, click Unlock, and click Start Sharing.
  5. Connect your Mac to another one via a USB data cable (with Type-A or USB-C plugs on either or both ends) or a Thunderbolt 3 or 4 cable.
  6. On the other Mac in the Finder, click the Network link in the sidebar to view the shared Mac’s volume.
  7. Click the Mac in the main window, click Connect As in the upper-right corner, select Guest as the user, and click Connect.

You can now transfer files between the two computers. When you’re finished, eject the mounted Mac volume by selecting it and dragging it to the Eject icon in the Dock or pressing ⌘-E.

Startup Security Utility

Apple took a harder line on startup security policy when they introduced Apple silicon Macs than they previously had with Intel models. macOS offers Full Security, which locks your Mac down to either its current version of macOS or any version Apple currently supports—typically a limited set. Reduced Security lets you run older versions of macOS that Apple previously approved to run on your hardware.

Almost unrelated, the “Allow accessories to connect” option lets you set a boot policy to restrict connections. For options, see the Mac settings worth changing.

Reduced Security lets you select or deselect the option to install signed legacy (or outdated) kernel extensions; and for remote management, which is used in schools and businesses, to control these kernel extensions and software updates. Some organizations may need specific older extensions for security software and may also want to delay automatic software updates to avoid breaking them.

People at a heightened level of risk could trust Reduced Security with just user management enabled for kernel extensions, since those extensions must be signed by “identified developers” (via Apple’s process) and require user steps to install, as described in Manage System Extensions.

If you don’t have Reduced Security enabled and try to install a system extension, the app installation explains what happened.

Proceed to click Open System Settings, and you see a note in System Settings > Privacy & Security.

Click Enable System Extensions and you see a dialog that provides a shortcut and offers abbreviated and somewhat misleading steps on enabling Reduced Security. If you want to proceed, click Shut Down in that dialog and then follow from step 2, below.

Starting from scratch, follow these steps:

  1. Restart in recovery mode. (See How to Restart in Recovery Mode.)
  2. Choose Utilities > Startup Security Utility.

Note: Apple requires an internet connection when you change the security policy, and you can hit a snag if you follow step 2 too quickly. If you see the error “An internet connection is required to change security policy,” quit the app (labeled Startup Disk when launched), wait for the Wi-Fi icon to show a connection in the menu bar, and launch the utility again. (An Ethernet connection doesn’t work.)

  1. The app launches. Click Unlock to mount the disk, which will be encrypted.
  2. Select an administrator user, enter the account’s password, and click Unlock.
  3. Select the drive if it’s not already selected.
  4. Click Security Policy.
  5. Select the level of security you want to apply and click OK.
  6. When prompted, select an administrator user, enter the account password, and click OK.
  7. “Applying security policy” appears. It may take several to tens of seconds to complete.
  8. Quit the utility and choose Apple menu > Restart.

Tip: Reduced Security disables Apple Pay on a Mac with Touch ID capability. See how to set up Touch ID and Face ID.

Permissive Security is an additional option that can’t be selected without disabling an even lower-level feature: System Integrity Protection. The Startup Security Utility then adds Permissive Security as an additional radio button. However, it’s not “no security,” but rather “experimental security”: it allows a very particular kind of installation, in which researchers and other niche users create custom kernels—the heart of the operating system—outside of the Apple-signed ecosystem of macOS versions compatible with Apple silicon Macs. It is exceedingly unlikely you would ever need it.

Recovery Assistant

Apple added Recovery Assistant in Tahoe to deal with situations in which macOS couldn’t start up correctly, and some sort of repair was required that needed the startup volume unmounted. If you encounter this, you will see a Recovery screen that explains the issue. You can also launch Recovery Assistant from macOS Recovery by choosing it from the Utilities menu.

The process works like this:

  1. At the Recovery screen, click Continue.
  2. Apple asks if you are willing to send them diagnostic data, and warns you about privacy issues. Click Don’t Send Data to Apple or Send Data to Apple.
  3. Click Start, and the assistant tries to resolve the problem.
  4. The assistant reports one of three states:

1.1. Your Mac was recovered successfully. Click Restart Mac.

1.1. No known issues were found. Click Restart Mac.

1.1. Your Mac could not be recovered. Oh, boy, it’s time to look into backups, consult an independent Apple expert or the Genius Bar at an Apple Store, or call Apple Support.

Share This Article

About Our Expert

Moses Johnson
ByMoses JohnsonVerified author
Senior Staff Writer, Help & How To
Follow:
Experience

I've been testing iOS, iPadOS, macOS, and watchOS for more than 10 years, focusing on tutorials, troubleshooting guides, how-to pieces, and other articles on Apple products.

Beyond NerdsModo, I've written how-to articles, troubleshooting guides and tutorials for a variety of other websites and publications, including iPhoneGeeks, GeeksModo and AARP Magazine.

I've used watchOS, iPadOS, and tvOS for years so I'm well versed in that world. I also know the visionOS quite well. I'm always working with an iPhone, iPad, Mac, and Apple Watch. And these days, I write a lot about Apple services, so that's become another key area for me.

My wife always jokes about all the Apple products we have around the house, but I manage to put them to good use for my articles. I like Apple computers, so I own a couple of Apple iMacs and several MacBooks. For my mobile life and work, I use an iPhone 16 Pro, iPad Pro, and iPad mini as well as an Apple Watch. But since I also write about Apple headsets, I own several Apple AirPods. Like any Apple user, I have a cabinet full of Accessories for Apple Watch, iPhone, iPad, Mac and Vision Pro. And when it's time to take a break from writing, I have an old Xbox 360 and Nintendo Wii, both of which I use for exercise and fitness games.

Areas of Expertise

iOS iPadOS macOS watchOS

Leave a Comment