{"id":52717,"date":"2026-07-24T14:07:33","date_gmt":"2026-07-24T18:07:33","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=52717"},"modified":"2026-07-24T14:07:33","modified_gmt":"2026-07-24T18:07:33","slug":"golden-gate-application-support-protection","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/07\/24\/golden-gate-application-support-protection\/","title":{"rendered":"Golden Gate Application Support Protection"},"content":{"rendered":"<p><a href=\"https:\/\/wojciechregula.blog\/post\/golden-gate-appdata-protection\/\">Wojciech Regu&#x142;a<\/a>:<\/p>\n<blockquote cite=\"https:\/\/wojciechregula.blog\/post\/golden-gate-appdata-protection\/\">\n<p>Looks like moving the user&rsquo;s TCC db to <tt>\/private\/var\/containers\/Data\/ProtectedSystem\/[UUID]\/Data\/Library\/Application Support\/com.apple.TCC\/<\/tt> was not the only change in the whole privacy castle of macOS 27. (What btw was a great move as now attackers with full disk access permissions can&rsquo;t modify your privacy settings)<\/p><p>macOS 27 quietly ships a new privacy mechanism I hadn&rsquo;t seen documented anywhere: it extends the <code>com.apple.macl<\/code> protection that has always guarded sandboxed apps&rsquo; <code>~\/Library\/Containers\/&lt;bundle-id&gt;\/Data<\/code> folders to a hand-picked set of <em>non-sandboxed<\/em> apps&rsquo; <code>~\/Library\/Application Support\/&lt;name&gt;<\/code> folders too. I noticed it by accident &mdash; Firefox&rsquo;s profile folder was suddenly inaccessible from Terminal, while MacPass, a password manager sitting right next to it, was wide open. That asymmetry didn&rsquo;t sit well with me, so I pulled the thread. It ends in a hardcoded app allowlist baked into <tt>\/usr\/libexec\/sandboxd<\/tt> (thx <a href=\"https:\/\/x.com\/ciphwall\">@ciphwall<\/a> for the hint), meant to be updated live via XProtect. <\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/05\/20\/hijacking-apps-using-archive-utility\/\">Hijacking Apps Using Archive Utility<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/04\/10\/privacy-t-show-intent-based-access\/\">Privacy & Security Settings Don&rsquo;t Show Intent-Based Access<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/02\/09\/resetting-tcc\/\">Resetting TCC<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/12\/18\/persistent-file-access-via-com-apple-macl-xattr\/\">Persistent File Access via com.apple.macl Xattr<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Wojciech Regu&#x142;a: Looks like moving the user&rsquo;s TCC db to \/private\/var\/containers\/Data\/ProtectedSystem\/[UUID]\/Data\/Library\/Application Support\/com.apple.TCC\/ was not the only change in the whole privacy castle of macOS 27. (What btw was a great move as now attackers with full disk access permissions can&rsquo;t modify your privacy settings)macOS 27 quietly ships a new privacy mechanism I hadn&rsquo;t seen documented [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-07-24T18:07:36Z","apple_news_api_id":"63ec9e69-f94d-495d-abe4-1c4c5f06a610","apple_news_api_modified_at":"2026-07-24T18:07:36Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AY-yeaflNSV2r5BxMXwamEA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[30,2784,355,48,1960],"class_list":["post-52717","post","type-post","status-publish","format-standard","hentry","category-technology","tag-mac","tag-macos-27","tag-privacy","tag-security","tag-transparency-consent-and-control-tcc"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=52717"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52717\/revisions"}],"predecessor-version":[{"id":52718,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/52717\/revisions\/52718"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=52717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=52717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=52717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}