macOS 27 locks down your data, without a word
macOS 27 quietly locks down the data of eight apps (browsers, wallets). A solid anti-theft move, but undocumented, and it breaks some backups.
On September 14, 2026, macOS 27 “Golden Gate” landed. In the release notes, nothing. In practice, Apple just locked down access to the data of eight applications, without writing it down anywhere.
What changed
On a Mac, every app stores its data in your home folder. For eight specific apps, macOS 27 now places an invisible tag on that storage, “only the real app is allowed in.”
The eight, the browsers Chrome, Brave, Edge and Firefox, the messaging app Discord, and three crypto wallets, Ledger Live, Exodus and Wasabi. Exactly the folders where your saved passwords, open sessions and wallet keys live.
By the way it works, a third-party program trying to read them would be blocked, even with Full Disk Access, the broadest macOS permission, the one that normally lets an app rummage through all your files. That is a deduction from the mechanism, not a guarantee Apple has stated.
The list is not carved into the system, it is delivered through XProtect, the anti-malware filter Apple updates in the background on your Mac. So Apple can extend it whenever it wants, with no new version of macOS.
The good news
The most common malware on Mac today does not wreck your machine. It is data thieves, the “infostealers”, they install once, siphon off your browser passwords, open sessions and crypto wallets, then leave. The folders macOS 27 just locked down are exactly their hunting ground.
Closing off access to these folders at the system level shuts the main way in for these attacks. On principle, it is solid.
The three catches
Three things worth saying plainly.
Apple has not documented it anywhere. Everything we know comes from the reverse engineering of security researcher Wojciech Reguła, later relayed by developer and blogger Michael Tsai. Nothing in the official security notes, nothing in the notes aimed at businesses. The only thing Apple confirms is the release date. Hard to trust a protection whose maker will not say how it works, or what it covers.
The list is short, and Apple holds the pen. Eight apps, not one more for now. Your third-party password manager probably is not on it. Neither is your messaging app. The protection is real, but narrow, and its scope does not depend on you.
It breaks legitimate uses, silently. Your homemade backup tool, a script, an rsync that copied these folders will run into it. The trap is that the failure can go unnoticed, the backup keeps going, just skips these apps, and does not always warn you. One breakage is already publicly documented on the testing-tools side.
If a backup starts failing
The typical symptom, an Operation not permitted error that shows up out of nowhere on a ~/Library/Application Support/... folder you copied without trouble until now. It is not a bug, and not a disk about to die. It is the new protection.
Two reflexes.
Do not fight the folder. Use the app’s built-in export or sync (your Firefox account, Chrome sync, your wallet’s recovery file) rather than copying the folder by hand.
Check your backup. Open your latest backup and make sure your browser profiles and wallet data are actually in there.
A good protection that comes in through the back door, with no manual. Take the gift, but go check your backups.