Apple has removed a controversial feature in macOS 11.2 beta 2 that allowed its own apps to bypass third-party firewalls, security tools, and VPNs
The ContentFilterExclusionList has been removed in macOS 11.2 beta 2. — Apple has removed a controversial feature from the macOS operating system …
ZDNetCatalin Cimpanu
Context & Ripple Effects
The reversal closes a loop opened in November, when a security researcher demonstrated on Big Sur that Apple's own apps could route around firewalls and VPNs via a hidden exclusion list. The feature sat at odds with how Apple polices the same category for others — as far back as 2017 it rejected a VPN-based ad blocker update and restricted iOS to Safari content blockers (removing VPN-based ad blockers), while separately pulling major VPN apps from the App Store in China.
Third-party firewall, security-tool, and VPN vendors regain visibility into traffic from Apple's own apps, restoring the filtering guarantees their macOS products were built on.
Apple avoids shipping the exclusion list in a public release, sparing enterprise and privacy-conscious customers a macOS version where its apps sit outside their security perimeter.
Second-order effects
Security vendors gain leverage to demand equal treatment of first-party system processes, since the episode proved public demonstration can force Apple to retract an exemption.
Rival platforms can cite the reversal in enterprise procurement debates over which OS respects customer-deployed network controls, pressuring Apple's security messaging.
Third-order effects
If demonstrated self-preferencing keeps getting walked back only after researchers expose it, platform gatekeeping becomes contestable by publicity rather than policy — pushing Apple toward codified rules for when its own software must obey the same restrictions it imposes on developers.
The trend: Platform owners' exemptions for their own software are increasingly exposed by independent researchers and forced into retreat, making self-preferencing a recurring fault line between Apple and the security tools built on its OS.
Omg we did it! 🤩 Thanks to the community feedback (and ya, bad press) Apple decided to remove the ContentFilterExclusionList (in 11.2 beta 2) Means socket filter firewalls (e.g. LuLu) can now comprehensively monitor/block all OS traffic!! Read more: https://www.patreon.com/... ht…
I had kind of missed this last autumn, but Apple made its own apps bypass firewalls and VPNs for a while? That sounds really bad... https://www.zdnet.com/...
“The bugs were related to @Apple...not having enough time to iron out bugs before Big Sur launch... Once Big Sur 11.2 is released, all Apple apps will once again be subject to firewalls & security tools.” Or launch could have waited? Perhaps? Because, trust? https://www.zdnet.com…
The other question is, was this Apple software engineer authorized to speak to the press? Strange that Apple refused to elaborate but the engineer did... Apple has many leaks, but AFAIK it's rare that they come from software engineering. https://twitter.com/...
Interesting if true. But fucking hell, if Apple would just be open and honest they could avoid a ton self-inflicted bad PR. Also once again Apple's yearly release schedule is trash and results in trash. https://twitter.com/... https://twitter.com/...
Apple seems to repeatedly self-deal when it comes to the access they provide their own apps. Corrections like this (in which their own apps like the App Store bypass a user's firewall) feel like mea culpas. https://www.patreon.com/... #ContentFilterExclusionList #Antitrust https:…
I guess it was me*. https://www.spiegel.de/... * No, definitely not at all. It's just good to see the occasional impact of a dedicated community on a company like Apple. https://twitter.com/...
List was removed in macOS 11.2 beta 2, as per @patrickwardle (see here: https://t.co/...) This was done for users' sake. See this evergreen tweet from Kevin last month: https://twitter.com/...