Security researcher demonstrates how Apple's apps on macOS Big Sur bypass firewalls and VPNs, an issue first brought to light in October
DON'T WORRY THOUGH, APPLE REALLY, REALLY, REALLY CARES ABOUT YOUR PRIVACY — For all of Apple's talk of being privacy-first, often its marketing speak … Source: @patrickwardle .
Context & Ripple Effects
Patrick Wardle's demonstration turns October's report into proof: on macOS Big Sur, Apple's own applications send traffic around firewalls and VPNs, so the tools users deploy to control their Macs simply do not see Apple's traffic. The timing compounds an uncomfortable week for Apple's security story — the same days brought a deep dive into the OCSP responder Apple uses to verify Mac app integrity, which concluded the critical service operates with little outside scrutiny.
The finding also slots into a longer arc in the coverage: back in 2017 researchers argued Apple was overselling its differential privacy protections (Apple disputed the study), and the following year would surface a notarization bypass letting unvetted apps run for months until Big Sur 11.3 patched it. The through-line is a gap between Apple's privacy-first marketing and how its platform actually behaves.
First-order effects
- Mac users running firewalls or VPNs on Big Sur have no visibility into — or control over — traffic from Apple's own apps, making those tools partially decorative for exactly the software they trust most.
- Wardle, who first raised the issue in October, now has a public demonstration that puts direct pressure on Apple to explain why its processes sit above the security stack it ships to customers.
Second-order effects
- Enterprise and consumer VPN vendors are forced to special-case or work around Apple's privileged processes, and the OCSP transparency critiques from the same week give them ammunition to demand documented exemptions rather than reverse-engineered ones.
- Security researchers gain a reusable template — probe what Apple's apps can do that third-party apps cannot — the same playbook Wardle applied years later when he showed macOS Background Task Management is trivially bypassed by sophisticated malware.
Third-order effects
- If the pattern holds — differential privacy claims questioned in 2017, firewall bypasses in 2020, notarization flaws and monitoring-tool bypasses after — Apple's 'privacy-first' positioning becomes a liability that regulators and auditors can test against mechanism, not marketing.
- MacOS security increasingly depends on trusting Apple's undocumented privileges rather than verifiable controls, pushing the platform toward the same transparency debates that surround closed verification services like the OCSP responder.
The trend: Apple's platform security is being reshaped by researchers exposing the gap between its privacy-first marketing and the privileged behavior of its own software, forcing transparency concessions one disclosure at a time.