SentinelOne flags core Mac processes after macOS 26.6 update

Apple's July security release is tripping SentinelOne's AI engine on legitimate system processes.

AppleThreat Staff
2 Min Read

Mac administrators are reporting false malware detections after Apple’s July 27 security release. On machines running macOS Tahoe 26.6, SentinelOne’s Static AI engine has been flagging legitimate system processes, including loginwindow, SystemUIServer, and the Spotlight indexing services mds and mdworker, with some reports adding the App Store to the list. The same release notes flag Spotlight index optimization ahead of macOS 27, which admins suspect is confusing the agent’s exclusion optimizer.

The false positives are causing more than alert noise. N-able’s status page describes system instability on affected endpoints, including menu bar and login screen problems, when the agent acts on the detections rather than merely reporting them. SentinelOne has confirmed the issue and is working through a multi-stage fix covering global exclusions, a Live Security Update, and a permanent correction in a future agent release.

SentinelOne shipped maintenance releases 26.1SP1 and 26.5.4SP1 on July 30. A configuration tweak also circulating among admins turns off the exclusion optimization setting in the console, which has stopped the false alarms without requiring an agent reinstall.

Vendors managing fleets are advising administrators to hold macOS 26.6 deployment until the fix is verified, apply the tweak to pilot groups first, and keep endpoint protection enabled while waiting.

Apple’s release itself is a major security update with more than 150 CVE fixes, so the guidance is to apply the SentinelOne mitigation rather than skip the macOS patch.

Share This Article