CIS Apple macOS 26 Tahoe Benchmark · Section 6

macOS Tahoe Applications: 8 Checks

Wartiva runs 8 checks for section 6, Applications, of the CIS Apple macOS 26 Tahoe Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 8 checks on this page

6.1 Finder

Ensure Show All Filename Extensions Is Enabled

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.1

Finding: Show all filename extensions is disabled.

Checks the Finder per-user setting that forces all filename extensions to be shown.

This rule fails when showAllExtensions is not true for a Finder user-settings object.

Rationale: Hidden extensions let a file masquerade as a benign type, aiding social-engineering and malware delivery.

Impact: Filenames display their true extension for every file.

Remediation

In Finder > Settings > Advanced, enable Show all filename extensions.

From the command line:

/usr/bin/sudo -u <username> /usr/bin/defaults write /Users/<username>/Library/Preferences/.GlobalPreferences.plist AppleShowAllExtensions -bool true
Framework mappings
  • CIS Controls v8: 2.3 Address Unauthorized Software
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-8 System Component Inventory; CM-10 Software Usage Restrictions; CM-11 User-installed Software
  • PCI DSS v4.0.1: 12.3.4 Annually assess whether hardware and software in use remain supported
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

6.3 Safari

Ensure Automatic Opening of Safe Files in Safari Is Disabled

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

Finding: Safari automatically opens safe files after download.

Checks the Safari per-user setting that auto-opens files deemed safe after download.

This rule fails when autoOpenSafeDownloads is not false for a Safari user-settings object.

Rationale: Auto-opening downloads can trigger malicious payloads without user action.

Impact: Downloaded files must be opened manually by the user.

Remediation

Install a configuration profile with PayloadType com.apple.Safari and set AutoOpenSafeDownloads to false.

Framework mappings
  • CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients; 9.6 Block Unnecessary File Types
  • NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code; SI-3 Malicious Code Protection; SI-8 Spam Protection
  • PCI DSS v4.0.1: 5.4.1 Detect phishing attempts and shield personnel through automated defenses
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

Ensure Safari Advertising Privacy Protection Is Enabled

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

Finding: Safari privacy-preserving ad measurement is disabled.

Checks the Safari privacy-preserving ad-click measurement (PCM) setting.

This rule fails when privateClickMeasurement is not true for a Safari user-settings object.

Rationale: PCM measures ad effectiveness without exposing individual user browsing to advertisers.

Impact: Ad attribution runs in a privacy-preserving manner.

Remediation

Install a configuration profile with PayloadType com.apple.Safari and set WebKitPreferences.privateClickMeasurementEnabled to true.

Framework mappings
  • CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Safari Prevents Cross-Site Tracking

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

Finding: Safari cross-site tracking prevention is not fully enabled.

Checks the three Safari storage-blocking policies that together prevent cross-site tracking.

This rule fails when blockStoragePolicy is not BLOCK_ALL or either WebKit storage-blocking policy is not BLOCK_THIRD_PARTY.

Rationale: Third-party storage is the primary mechanism for cross-site tracking of users.

Impact: Cross-site trackers can no longer persist storage between sites.

Remediation

Install a configuration profile with PayloadType com.apple.Safari: set BlockStoragePolicy to 2, WebKitPreferences.storageBlockingPolicy to 1, and WebKitStorageBlockingPolicy to 1.

Framework mappings
  • CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code
Risk
Unprotected Data
MITRE ATT&CK tactic
Command and Control / Exfiltration (TA0011, TA0010)

Ensure Safari Shows the Full Website Address

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

Finding: Safari does not show the full website address.

Checks the Safari setting that shows the complete URL in the address bar.

This rule fails when showFullURL is not true for a Safari user-settings object.

Rationale: Showing the full URL helps users spot look-alike or deceptive phishing domains.

Impact: The address bar shows the complete URL instead of only the domain.

Remediation

Install a configuration profile with PayloadType com.apple.Safari and set ShowFullURLInSmartSearchField to true.

Framework mappings
  • CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code
Risk
High Profile Threat
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Safari Status Bar Is Shown

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

Finding: Safari status bar is hidden.

Checks the Safari setting that shows the status bar revealing link destinations on hover.

This rule fails when showStatusBar is not true for a Safari user-settings object.

Rationale: The status bar reveals a link's true destination before the user clicks, exposing deceptive links.

Impact: Hovering a link shows its destination in the status bar.

Remediation

Install a configuration profile with PayloadType com.apple.Safari and set ShowOverlayStatusBar to true.

Framework mappings
  • CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
  • NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-18 Mobile Code
Risk
High Profile Threat
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure Safari Warns When Visiting a Fraudulent Website

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

Finding: Safari fraudulent-website warning is disabled.

Checks the Safari per-user setting that warns before loading known phishing or malware sites.

This rule fails when warnFraudulentWebsites is not true for a Safari user-settings object.

Rationale: The warning is a first-line defense against phishing and drive-by malware sites.

Impact: Safari displays a warning interstitial for known fraudulent sites.

Remediation

Install a configuration profile with PayloadType com.apple.Safari and set WarnAboutFraudulentWebsites to true.

Framework mappings
  • CIS Controls v8: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients; 9.3 Maintain and Enforce Network-Based URL Filters
  • NIST SP 800-53 Rev. 5: CM-10 Software Usage Restrictions; SC-7 Boundary Protection; SC-18 Mobile Code
  • PCI DSS v4.0.1: 1.2.6 Add security features that offset risk from active insecure services; 1.4.2 Permit untrusted-to-trusted inbound traffic only to authorized public services
Risk
High Profile Threat
MITRE ATT&CK tactic
Initial Access (TA0001)

6.4 Terminal

Ensure Terminal Secure Keyboard Entry Is Enabled

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.4

Finding: Terminal Secure Keyboard Entry is disabled.

Checks Terminal.app Secure Keyboard Entry, which blocks other apps from intercepting keystrokes.

This rule fails when terminalSecureKeyboardEntry is not true for a Terminal user-settings object.

Rationale: Without Secure Keyboard Entry, other processes can capture keystrokes (including passwords) typed in Terminal.

Impact: Other applications can no longer read keystrokes entered in Terminal.

Remediation

Install a configuration profile with PayloadType com.apple.Terminal and set SecureKeyboardEntry to true.

From the command line:

/usr/bin/defaults write -app Terminal SecureKeyboardEntry -bool true
Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Unprotected Data
MITRE ATT&CK tactic
Credential Access (TA0006)