Tahoe’s Gatekeeper resists every attempt to switch it off

Testing shows Tahoe 26.6 no longer lets admins switch off Gatekeeper and XProtect protections.

AppleThreat Staff
2 Min Read

Macs running the current Tahoe release keep their built-in malware guards switched on even when administrators try to turn them off. Fresh testing by the Eclectic Light Company shows the classic command that used to disable Gatekeeper no longer does what its name promises.

On Tahoe 26.6, running spctl –master-disable and allowing any signed app only widens what can launch. The xprotect status tool still reports both on-demand launch scans and background scans as enabled, and installing a profile that sets EnableAssessment to false produces the same result.

The shift arrived with Sequoia. Apple’s documentation for spctl now says operations that modify the rule database or the global state of the assessment subsystem are no longer supported, yet the master-disable option remains and still broadens permitted apps. Observed behavior and documented behavior no longer match.

XProtect Remediator’s periodic scans appear impossible to switch off too. The only control exposed in the GUI is the popup menu in Privacy and Security settings, which limits launches to the App Store alone or the App Store plus known developers.

For security teams the change is a quiet win. Gatekeeper and XProtect stay active even on machines where admins tried to relax protections, shrinking the attack surface for fleets that lean on Apple’s built-in controls instead of third-party endpoint agents.

Share This Article