Apple Updates Platform Security Guide, Says Kernel Extensions Won't Be Supported on Future Apple Silicon Macs

Apple today shared an updated version of its Platform Security Guide [PDF], providing a comprehensive overview of the latest security advancements across iOS 14, iPadOS 14, macOS Big Sur, tvOS 14, watchOS 7, and more.

apple devices mac iphone ipad watch collage
For example, the guide provides security details about Safari's optional Password Monitoring feature on iOS 14 and macOS Big Sur, which automatically keeps an eye out for any saved passwords that may have been involved in a data breach. Apple also outlines the security of its new digital car keys feature on the iPhone and Apple Watch.

Apple updated its "commitment to security" preamble, touting the security advantages of Apple-designed chips across the iPhone, iPad, Apple Watch, and Mac:

Apple continues to push the boundaries of what's possible in security and privacy. This year Apple devices with Apple SoC's across the product lineup from Apple Watch to iPhone and iPad, and now Mac, utilize custom silicon to power not only efficient computation, but also security. Apple silicon forms the foundation for secure boot, Touch ID and Face ID, and Data Protection, as well as system integrity features never before featured on the Mac including Kernel Integrity Protection, Pointer Authentication Codes, and Fast Permission Restrictions. These integrity features help prevent common attack techniques that target memory, manipulate instructions, and use javascript on the web. They combine to help make sure that even if attacker code somehow executes, the damage it can do is dramatically reduced.

New sections have been added for Macs with Apple silicon, outlining the security of the boot process, boot modes, startup disk, Rosetta 2 translation process for running Intel-based Mac apps, FileVault, Activation Lock, and more.

As expected, the guide confirms that kernel extensions will not be supported on future Macs with Apple silicon (emphasis ours):

In addition to enabling users to run older versions of macOS, Reduced Security is required for other actions that can put a user's system security at risk, such as introducing third-party kernel extensions (kexts). Kexts have the same privileges as the kernel, and thus any vulnerabilities in third-party kexts can lead to full operating system compromise. This is why developers are being strongly encouraged to adopt system extensions before kext support is removed from macOS for future Mac computers with Apple silicon.

macOS Catalina was the last version of macOS to fully support kernel extensions. Apple says kernel extensions are no longer recommended for macOS, noting that they pose a risk to the integrity and reliability of the operating system.

Starting with macOS Catalina, developers have been able to use system extensions that run in user space rather than at the kernel level. System extensions running in user space are granted only the privileges necessary to perform their specified function, which increases the stability and security of macOS, according to Apple.

Apple includes a document revision history section in the Platform Security Guide with a list of all new and updated information.

Apple also has a new Security Certifications and Compliance Center.

Popular Stories

iphone 16 pro max

iPhone 16 Users Complain About Excessive iOS 18 Battery Drain

Thursday October 17, 2024 4:06 pm PDT by
Some iPhone 16 and iPhone 16 Pro users have been experiencing excessive and unexplainable battery drain, according to complaints on Reddit, the Apple Support Communities, and the MacRumors forums. While many of the reports are from iPhone 16 users, older iPhones running iOS 18 may also be experiencing battery life issues. There is a long-running iOS 18 battery life complaint thread on MacRumo...
ipad mini 7

Apple Unveils New iPad Mini With A17 Pro Chip and Apple Intelligence

Tuesday October 15, 2024 6:07 am PDT by
Apple today announced a significant upgrade to the iPad mini, now featuring an A17 Pro chip and support for the company's new Apple Intelligence system. The refreshed seventh-generation tablet maintains its compact 8.3-inch design while offering notable performance improvements and new capabilities. Subscribe to the MacRumors YouTube channel for more videos. The A17 Pro chip brings a 30%...
scary fast apple event

Is an Apple Event Still Likely This October Following Today's Surprise iPad Mini 7 Announcement?

Tuesday October 15, 2024 1:57 pm PDT by
Apple has held an October event in three out of the past four years, but is an event this month still likely after today's surprise iPad mini 7 announcement? While some Apple enthusiasts believe that the iPad mini 7 being unveiled in a press release today means that Apple is unlikely to hold an October event this year, the announcement does not entirely rule out the possibility. Last year,...
Apple Intelligence iPhone 16

iOS 18.2 Expected to Add These Additional Apple Intelligence Features

Tuesday October 15, 2024 12:05 pm PDT by
In its press release for the iPad mini 7 today, Apple reiterated that additional Apple Intelligence features will be rolling out "over the next several months." Below, we outline Apple Intelligence features that are expected to be added as part of iOS 18.2, which is expected to be released to the public in December. Apple Intelligence in More Languages During its iPhone 16 event last...
ipad 10th gen blue

Apple Cuts Entry-Level iPad Price in Europe, Removes Charger From Box

Wednesday October 16, 2024 4:41 am PDT by
Yesterday we noted that the new iPad mini 7 does not come with a charger in the box when sold in European countries, and it turns out that the same now also applies to entry-level iPads sold by Apple across the continent. Since its release in 2022, Apple's most affordable iPad has come with a USB-C charger in Europe, but the debut of the new iPad mini on Tuesday would have left it as the...
m3 mbp space black

Apple's Supply Chain Gears Up for MacBook Pro Models With M4 Chips

Wednesday October 16, 2024 8:36 am PDT by
Apple's supply chain is gearing up for new MacBook Pro models with M4 chips, which are expected to be announced this month, according to DigiTimes. "Apple is expected to unveil new MacBook Pro models equipped with the latest M4 chip in October, which could boost related component shipments," says the paywalled report, published today. "This trend is evident in the revenue reports from...
Apple Pay Klarna

Apple Announces New Klarna and PayPal Integrations for Apple Pay on iOS 18

Thursday October 17, 2024 7:22 am PDT by
In June, Apple discontinued its "buy now, pay later" service called Apple Pay Later, which let qualifying customers split a purchase made with Apple Pay into four equal payments over six weeks, with no interest or fees. Instead, Apple said customers in the U.S. would be able to apply for loans from select other "buy now, pay later" services when they check out with Apple Pay on the web and in...
chatgpt siri

Apple Preparing to Add ChatGPT Integration to Siri

Thursday October 17, 2024 2:59 pm PDT by
Apple is working behind the scenes to get ready to add new Apple Intelligence features to iOS 18, iPadOS 18, and macOS 15. We'll get the first set in the iOS 18.1, iPadOS 18.1, and macOS 15.1 updates, but Apple is preparing for the next batch, too. In backend code, MacRumors has discovered new references to Siri's ChatGPT integration as Apple prepares to implement ChatGPT support. Siri code...

Top Rated Comments

chucker23n1 Avatar
48 months ago
"Apple continues to push the boundaries of what's possible in security and privacy."

I mean, sure, yes. But also: "Apple continues to reduce the ceiling of what's possible in macOS."
Score: 28 Votes (Like | Disagree)
asiga Avatar
48 months ago
At the end, their goal is that MacOS is just iPadOS with Terminal and Xcode.
Score: 26 Votes (Like | Disagree)
jameslmoser Avatar
48 months ago
Anyone surprised by this hasn't been paying attention. Apple is transforming Macs into Apple Service Appliances, and allowing you to customize your OS and install stuff from other places than the App store or developer signed Apps doesn't make them any money.
Score: 16 Votes (Like | Disagree)
aednichols Avatar
48 months ago
Herding developers to run app code in userspace instead of the kernel is just a good idea in general.

I've already been avoiding kext-based apps where possible for years.
Score: 16 Votes (Like | Disagree)
leman Avatar
48 months ago
Anyone surprised by this has not been following macOS development for the last couple of years. Kernel extensions are out, userland drivers are in.


I mean, sure, yes. But also: "Apple continues to reduce the ceiling of what's possible in macOS."
If DriverKit supports enough relevant use cases, I don't see a problem.


Apple is inching MacOS to full Mach, which would be awesome... killing kernel extensions before having third-party GPU support will be interesting. What is old is new again https://en.wikipedia.org/wiki/MkLinux
There won't be any third party GPU support on Apple Silicon. Why would Apple sabotage the developer and user experience ecosystem they have been painstakingly bulding?


VirtualBox
Made irrelevant by the new virtualization framework. Parallels Preview runs on M1 without any kernel extensions.
Score: 14 Votes (Like | Disagree)
jrlcopy Avatar
48 months ago
Umm.... that's like a decent amount of professional apps.
Score: 8 Votes (Like | Disagree)