macOS Big Sur 11.2 Beta 2 Removes Feature Letting Apple Apps Bypass Third-Party Firewalls and VPNs

macOS Big Sur 11.2 beta 2, which was released yesterday, eliminates a feature that allowed Apple apps bypass third-party firewalls, security tools, and VPN apps, according to reports from ZDNet and security researcher Patrick Wardle.

First Look Big Sur Feature2
‌macOS Big Sur‌ 11 included a ContentFilterExclusionList that let Apple's apps like the App Store, Maps, iCloud, and more to avoid firewall and VPN apps that users had installed. These apps were not able to filter or inspect traffic for some built-in Apple apps.

Security researchers believed that the feature, found last October, was a major security risk as malware could be designed to latch on to a legitimate Apple app and bypass security software. Users who had VPNs installed also risked exposing their real IP address and location to Apple's apps.


Apple told ZDNet last year that the list was temporary and the result of a series of bugs related to the deprecation of network kernel extensions in ‌macOS Big Sur‌. Apple has been addressing those bugs, and in the second beta of ‌macOS Big Sur‌ released yesterday, removed the ContentFilterExclusionList from the macOS code.

When ‌macOS Big Sur‌ 11.2 sees a release, Apple apps will be compatible with VPN apps and will no longer be able to bypass firewalls and other security tools.

Related Roundup: macOS Big Sur
Related Forum: macOS Big Sur

Top Rated Comments

hortod1 Avatar
9 months ago
The older I get the more this might as well be a foreign language

<sigh>
Score: 10 Votes (Like | Disagree)
sideshowuniqueuser Avatar
9 months ago
'We have another candidate for our "Is This A Feature Or Is This A Bug?" bingo.'

Ha ha that cracks me up!
Score: 7 Votes (Like | Disagree)
BWhaler Avatar
9 months ago
It should have always been this way, but I’m pleased Apple is making the appropriately change quickly. Thank you.
Score: 7 Votes (Like | Disagree)
chucker23n1 Avatar
9 months ago

The older I get the more this might as well be a foreign language

<sigh>
Apple recently started requiring third party software who want to control network traffic (such as firewalls) to intercept it a different way. They documented and explained the new way, and it's been mostly fine. However, they then exempted some of their own software from this new way.

A security researcher example: they want to observe how an app communicates with the network, how its behavior changes when they limit some of that communication, etc. They weren't able to do that with some of Apple's apps. For example, if App Store or Find My had a security bug related to network communication, they would have a hard time finding out. Not only can they not control the traffic from those services, they can't even see it.

A more general-purpose example: you're on cellular (or some other metered connection), and use an app like Trip Mode to limit data usage. Well, you can't see the data some of Apple's stuff uses. App Store or Software Update download a large update in the background? Trip Mode won't be able to tell you.

There were probably some reasons Apple did all this in the first place (for example, one might argue that macOS needs to be able to download updates to Xprotect malware definitions no matter what), but there's also a fair bit of hubris involved. It feels like once they did decide to make that exemption list, all kinds of software teams internally signed up to be added, and that's just opening the floodgates for trouble.

Anyway, all this, it appears, is now resolved.
Score: 5 Votes (Like | Disagree)
-BigMac- Avatar
9 months ago
Apple allowed to bypass firewalls/security software?

What an unfortunate “bug” this mustve been for Apple before it was found ;)
Score: 5 Votes (Like | Disagree)
Apple_Robert Avatar
9 months ago

Excellent news - been aching to move to Big Sur (love the place - LOL) but holding back until VPN's would function there (plus other Objective see tools) - wife is itching to do so for work and will do so as soon as the update to 11.2 is out.
SurfShark is the only brand name VPN I have seen with Silicon support thus far. Nord and PIA are dragging their software heels.
Score: 3 Votes (Like | Disagree)

Top Stories

macOS Big Sur Feature Purple

Apple Releases macOS Big Sur 11.3.1 With Fixes for WebKit Security Issues

Monday May 3, 2021 10:26 am PDT by
Alongside iOS 14.5.1 and watchOS 7.4.1, Apple today also released macOS Big Sur 11.3.1, which the company says "provides important security updates". According to the full security notes for the release, it addresses a memory corruption issue and an integer overflow in WebKit that could both be exploited using maliciously crafted web content. Apple says it aware of a report that these issues ...
macOS 11

Apple Seeds First Beta of macOS Big Sur 11.2 to Developers

Wednesday December 16, 2020 2:33 pm PST by
Apple today seeded the first beta of an upcoming macOS Big Sur 11.2 update to developers for testing purposes, with the new beta coming two days launch of macOS Big Sur 11.1, the first major update to he operating system first launched in November. Developers can download the ‌macOS Big Sur‌ 11.2 beta using the Software Update mechanism in System Preferences after installing the proper...
macOS Big Sur Feature Blue

Update to macOS 11.4 NOW - Someone Could Be Spying On You

Sunday May 30, 2021 9:40 am PDT by
Apple's recently released macOS Big Sur 11.4 update addresses a serious security vulnerability, so all users should complete the software update immediately. Jamf, a mobile device management company, raised a major security issue in macOS Big Sur that allowed attackers to piggyback apps like Zoom to surreptitiously take screenshots and record the screen. The exploit allowed a user's Privacy...
macOS Big Sur Feature Purple

Apple Seeds First Beta of macOS Big Sur 11.4 to Developers [Update: Public Beta Available]

Wednesday April 21, 2021 10:26 am PDT by
Apple today seeded the first beta of an upcoming macOS Big Sur 11.4 update to developers for testing purposes, with the new beta coming while the macOS 11.3 beta is still in testing. Developers can download the ‌‌‌macOS Big Sur‌‌‌ 11.4 beta using the Software Update mechanism in System Preferences after installing the proper profile from the Apple Developer Center. According...
macOS Big Sur Feature Purple

Apple Seeds Second Beta of macOS Big Sur 11.4 to Developers [Update: Public Beta Available]

Tuesday May 4, 2021 10:19 am PDT by
Apple today seeded the second beta of an upcoming macOS Big Sur 11.4 update to developers for testing purposes, with the new beta coming two weeks after the release of the first macOS Big Sur 11.4 beta. Developers can download the ‌‌‌macOS Big Sur‌‌‌ 11.4 beta using the Software Update mechanism in System Preferences after installing the proper profile from the Apple Developer...
macOS Big Sur Feature Purple

Apple Seeds macOS Big Sur 11.4 Release Candidate to Developers

Monday May 17, 2021 10:17 am PDT by
Apple today seeded the release candidate version of an upcoming macOS Big Sur 11.4 update to developers for testing purposes, with the new beta coming two weeks after the release of the third macOS Big Sur 11.4 beta. Developers can download the ‌‌‌macOS Big Sur‌‌‌ 11.4 beta using the Software Update mechanism in System Preferences after installing the proper profile from the...
macOS Big Sur Feature Orange

Apple Releases macOS Big Sur 11.2.3 With WebKit Security Fix

Monday March 8, 2021 10:12 am PST by
Apple today released macOS Big Sur 11.2.3, the fifth update to the macOS Big Sur operating system that launched in November. macOS Big Sur 11.2.3 comes two weeks after the release of macOS 11.2.2, a bug fix update. The new ‌‌‌‌‌macOS Big Sur‌‌‌‌ 11.2.3 update can be downloaded for free on all eligible Macs using the Software Update section of System Preferences. Apple...
iOS 14 on iPhone feature emergency

Apple Seeds First Public Betas of iOS 14.7, iPadOS 14.7, and macOS Big Sur 11.5

Thursday May 20, 2021 10:11 am PDT by
Apple today seeded the first public betas of iOS 14.7, iPadOS 14.7, and macOS Big Sur 11.5 to public beta testers, one day after seeding first betas to developers. Public beta testers who have signed up for the beta testing program can download the iOS and iPadOS‌ 14.7 updates over the air after installing the proper certificate from the Public Beta website on an iOS device. macOS Big Sur...
First Look Big Sur Feature2

Apple Seeds Release Candidate Version of Upcoming macOS Big Sur 11.1 Update to Developers [Update: Public Beta Available]

Thursday December 10, 2020 10:12 am PST by
Apple today seeded the release candidate version of an upcoming macOS Big Sur 11.1 update to developers for testing purposes, with the update coming one week after the release of the second beta and a month after the launch of macOS Big Sur 11.0.1, the release version of the software. Developers can download the macOS Big Sur 11.1 beta using the Software Update mechanism in System...
macOS 11

Apple Seeds Second Beta of macOS Big Sur 11.2 to Developers [Update: Public Beta Available]

Wednesday January 13, 2021 10:02 am PST by
Apple today seeded the second beta of an upcoming macOS Big Sur 11.2 update to developers for testing purposes, with the new beta coming a month after the first beta and two months after the initial macOS Big Sur release. Developers can download the ‌‌macOS Big Sur‌‌ 11.2 beta using the Software Update mechanism in System Preferences after installing the proper profile from the Apple ...