← All guides

XProtect on Mac: the antivirus your Mac already runs

Your Mac has been scanning itself for malware since the day you switched it on. What XProtect, XProtect Remediator, Gatekeeper and notarization actually do, how to check the version you have, and the honest answer on whether you need antivirus as well.

Plumby TeamAug 8, 2026Updated Aug 9, 20268 min read
XProtect on Mac: the antivirus your Mac already runs

XProtect is the antivirus already built into your Mac. Apple's own words: macOS "includes built-in antivirus technology called XProtect for the signature-based detection and removal of malware." It has no icon, no window and no Scan button, and it has been running since you first turned the machine on.

The silence is the problem. Protection you never see is protection you can be sold against, and "Macs have no antivirus" remains one of the most profitable false sentences on the internet.

The layers, in the order they act

Apple describes its malware defences in three stages: stop distribution, block what turns up anyway, clean up whatever ran. Four named pieces do that work.

Notarization happens before the software reaches you. A developer shipping an app outside the App Store uploads it to Apple's notary service, which scans it for malicious content and checks the code signing. Apple is careful to say this "is not App Review": no human judges whether the app is any good, an automated system decides it isn't obviously malware.

Gatekeeper acts the moment you open something. It verifies that the software is from an identified developer, is notarized, and hasn't been altered since. The first time you open a downloaded app it asks you directly, because the case it exists to catch is you being tricked. If you have seen syspolicyd burning CPU, that is Gatekeeper at work; the certificate half of the check belongs to trustd.

Sequoia tightened this. The old trick of Control-clicking an unnotarized app and choosing Open is gone; you now have to allow it deliberately in System Settings > Privacy & Security, which is slower on purpose.

XProtect is the scanner. It uses YARA rules, the same signature format security researchers write, and runs when an app is first launched, when an app changes on disk, and when Apple updates the signatures.

XProtect Remediator is the cleanup crew. It replaced the old Malware Removal Tool in 2022 and runs a set of modules that sweep the Mac in the background on a timer. When one matches, it tries to remove what it found. You are not told; the detection goes to the system log and nowhere else.

The updates arrive without a macOS upgrade

XProtect's signatures are delivered "independent from system updates", and this matters most on older machines. A Mac on Sonoma 14 receives the same rule updates as one on the newest release, and macOS checks daily by default. You do not have to upgrade the operating system to keep malware definitions current. Staying a version behind still costs you macOS's own security fixes, a separate argument.

Sequoia changed the plumbing. On Sonoma there is one XProtect bundle, in /Library/Apple/System/Library/CoreServices, swapped out when an update lands. From Sequoia onward the copy in use sits at /var/protected/xprotect and arrives over iCloud, while the old location keeps updating as a backup. Same version number at the end.

A note on cadence: for most of the last eighteen months XProtect has been updated roughly weekly, though not dependably. In mid-2026 it went thirty-seven days without one, and XProtect Remediator has sat on version 157 since February 2026. Apple never publishes what an update contains, so treat "always current" as a claim to check.

One setting keeps it flowing. In System Settings > General > Software Update, click the (i) beside Automatic Updates and leave "Install Security Responses and system files" on. If you turned automatic updates off, that is the switch to put back.

How to check the version you have

Start without the Terminal.

Open System Information (Applications > Utilities). In the sidebar, under Software, click Installations and sort by date. Two entries matter: XProtectPlistConfigData is the signature data, XProtectPayloads is XProtect Remediator. On the Mac this guide was written on, in August 2026, those read 5354 (installed 6 August) and 157.

Howard Oakley posts the version and date of every XProtect release at eclecticlight.co; if your number sits well behind his latest, something is stuck.

On Sequoia and later there is a Terminal command too. Open Terminal and type:

xprotect version

That reads a version number and prints it. It does not scan, download, change or delete anything, and it won't ask for your password. Its companion xprotect status prints whether launch scans and background scans are enabled, and is equally read-only. On macOS 14 the command doesn't exist, so System Information is your route.

If the number really is stale, sudo xprotect update forces it. That one asks for your admin password, because unlike the other two it writes.

What XProtect doesn't do

It is signature-based, so it catches malware Apple has written a rule for, and a new family stays invisible until that rule exists. It also cannot save you from your own consent. The commonest way onto a Mac now is a person pasting a Terminal command from a web page, or running a fake updater, and no signature intervenes when you type your password.

The scanning is more conditional than it sounds. Since 2025, XProtect Remediator runs fast scans every six hours, which continue on battery, plus daily standard scans and weekly slow ones, neither of which run on battery. A laptop that lives unplugged can go days without a full sweep, and nothing tells you.

It won't tidy up an ad-injecting browser extension you installed yourself either, and it isn't looking for Windows malware you might forward to a colleague.

What Mac malware actually is

Not viruses in the old sense. Self-replicating things that spread on their own stopped being the Mac's problem long ago.

Apple's own remediator gives the clearest picture of what replaced them. In 2023 it carried nineteen scanning modules, four aimed at adware outright: Adload, Genieo, Pirrit and Trovi, all browser hijackers and ad injectors. The Adload module alone now holds more than a thousand detection rules. That is where Apple spends its effort, because that is what keeps turning up. Malwarebytes' 2020 telemetry put unwanted programs at 76% of its Mac detections and adware at 22%, malware proper near 1.5%. A vendor's number, six years old: read it as the shape of the problem, not today's count.

The serious end has moved since. Objective-See's review of 2025 found infostealers were "without a doubt, the most common type of new macOS malware observed", delivered through fake updates, malicious ads and that copy-a-command trick. They get installed by people rather than caught like a cold.

Apple has never claimed the Mac is clean. Craig Federighi, under oath in 2021: "Today, we have a level of malware on the Mac that we don't find acceptable and that is much worse than iOS."

So, do you need antivirus on a Mac?

For most people, no. The layers above handle the ordinary case and cost nothing.

There are exceptions:

  • Your work or school requires it on a managed Mac. Not your decision.
  • You install a lot of software from outside the App Store, especially cracked or torrented. That is where detections concentrate.
  • You pass files to Windows users and would rather not forward something along.
  • Something has already gone wrong and you want a second opinion.

Weigh the cost. A resident scanner wants Full Disk Access and watches file activity all day, which on an eight-gigabyte or Intel Mac is a daily tax on a machine with nothing spare. If that is you, why your Mac is slow beats a shopping list.

Weigh the marketing too. The loudest voices telling you a Mac needs protection are the ones selling it. This is the category that produced the scareware history in are Mac cleaners safe, the counterfeit downloads in is CleanMyMac safe, the reputation behind MacKeeper alternatives, and the same prior question as do you need a Mac cleaner. Objective-See publishes its Mac security tools free.

If you think something is already on there

Look before you install anything, because adware leaves visible traces.

Open System Settings > General > Login Items & Extensions and read it for background items you don't recognise. Check your browser's extensions, homepage and default search engine, which is the first thing a hijacker changes. If a Device Management or Profiles pane has appeared, look at what put it there. Then remove the app that came with the problem properly rather than dragging it to the Trash (uninstalling apps completely covers that), and restart.

Don't disable Gatekeeper as a troubleshooting step. In current macOS you largely can't anyway: spctl --master-disable no longer switches off Gatekeeper or on-demand XProtect, it only lets signed-but-unnotarized apps run. And if a page tells you to paste a command to fix an infection, that page is the infection.

Before you pay for protection

Your Mac is not defenceless and it is not invincible. It ships with a notarization service upstream, a gatekeeper at launch, a signature scanner and a background remover, all updated separately from macOS, all invisible unless you go looking, and none of them a substitute for pausing before you type your password. Knowing which is which is what stops a pop-up costing you a subscription.

Plumby puts that XProtect version on screen with how long ago it was installed, next to what macOS reports about FileVault, SIP, Gatekeeper and the firewall, and links to the settings pane if you want to change one. It shows those states as information rather than a verdict. It runs no scan and it is not antivirus; it reads the same numbers you could read yourself and saves you the trip.

See it, don’t guess it.
Plumby shows where your disk, memory, and processes actually go, then clears what’s safe, only when you say so.

Related guides