---
title: CIS macOS Tahoe Applications: 8 Checks | Wartiva
description: Wartiva's 8 checks for section 6, Applications, of the CIS Apple macOS 26 Tahoe Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html
updated: 2026-10-07
---

CIS Apple macOS 26 Tahoe Benchmark · Section 6

# macOS Tahoe Applications: 8 Checks

Wartiva runs 8 checks for section 6, Applications, of the CIS Apple macOS 26 Tahoe Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 6.1 Finder

### [Ensure Show All Filename Extensions Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#show-all-filename-extensions-is-enabled)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.1

**Finding:** Show all filename extensions is disabled.

Checks the Finder per-user setting that forces all filename extensions to be shown.

This rule fails when `showAllExtensions` is not `true` for a Finder user-settings object.

**Rationale:** Hidden extensions let a file masquerade as a benign type, aiding social-engineering and malware delivery.

**Impact:** Filenames display their true extension for every file.

#### Remediation

In **Finder > Settings > Advanced**, enable **Show all filename extensions**.

From the command line:

```sh
/usr/bin/sudo -u <username> /usr/bin/defaults write /Users/<username>/Library/Preferences/.GlobalPreferences.plist AppleShowAllExtensions -bool true
```

Framework mappings

- **CIS Controls v8**: 2.3 Address Unauthorized Software
- **NIST SP 800-53 Rev. 5**: CM-7 Least Functionality; CM-8 System Component Inventory; CM-10 Software Usage Restrictions; CM-11 User-installed Software
- **PCI DSS v4.0.1**: 12.3.4 Annually assess whether hardware and software in use remain supported

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

## 6.3 Safari

### [Ensure Automatic Opening of Safe Files in Safari Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#automatic-opening-of-safe-files-in-safari-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

**Finding:** Safari automatically opens safe files after download.

Checks the Safari per-user setting that auto-opens files deemed safe after download.

This rule fails when `autoOpenSafeDownloads` is not `false` for a Safari user-settings object.

**Rationale:** Auto-opening downloads can trigger malicious payloads without user action.

**Impact:** Downloaded files must be opened manually by the user.

#### Remediation

Install a configuration profile with **PayloadType `com.apple.Safari`** and set **AutoOpenSafeDownloads** to `false`.

Framework mappings

- **CIS Controls v8**: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients; 9.6 Block Unnecessary File Types
- **NIST SP 800-53 Rev. 5**: CM-10 Software Usage Restrictions; SC-18 Mobile Code; SI-3 Malicious Code Protection; SI-8 Spam Protection
- **PCI DSS v4.0.1**: 5.4.1 Detect phishing attempts and shield personnel through automated defenses

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Safari Advertising Privacy Protection Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#safari-advertising-privacy-protection-is-enabled)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

**Finding:** Safari privacy-preserving ad measurement is disabled.

Checks the Safari privacy-preserving ad-click measurement (PCM) setting.

This rule fails when `privateClickMeasurement` is not `true` for a Safari user-settings object.

**Rationale:** PCM measures ad effectiveness without exposing individual user browsing to advertisers.

**Impact:** Ad attribution runs in a privacy-preserving manner.

#### Remediation

Install a configuration profile with **PayloadType `com.apple.Safari`** and set **WebKitPreferences.privateClickMeasurementEnabled** to `true`.

Framework mappings

- **CIS Controls v8**: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
- **NIST SP 800-53 Rev. 5**: CM-10 Software Usage Restrictions; SC-18 Mobile Code

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Safari Prevents Cross-Site Tracking](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#safari-prevents-cross-site-tracking)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

**Finding:** Safari cross-site tracking prevention is not fully enabled.

Checks the three Safari storage-blocking policies that together prevent cross-site tracking.

This rule fails when `blockStoragePolicy` is not `BLOCK_ALL` or either WebKit storage-blocking policy is not `BLOCK_THIRD_PARTY`.

**Rationale:** Third-party storage is the primary mechanism for cross-site tracking of users.

**Impact:** Cross-site trackers can no longer persist storage between sites.

#### Remediation

Install a configuration profile with **PayloadType `com.apple.Safari`**: set **BlockStoragePolicy** to `2`, **WebKitPreferences.storageBlockingPolicy** to `1`, and **WebKitStorageBlockingPolicy** to `1`.

Framework mappings

- **CIS Controls v8**: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
- **NIST SP 800-53 Rev. 5**: CM-10 Software Usage Restrictions; SC-18 Mobile Code

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Safari Shows the Full Website Address](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#safari-shows-the-full-website-address)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

**Finding:** Safari does not show the full website address.

Checks the Safari setting that shows the complete URL in the address bar.

This rule fails when `showFullURL` is not `true` for a Safari user-settings object.

**Rationale:** Showing the full URL helps users spot look-alike or deceptive phishing domains.

**Impact:** The address bar shows the complete URL instead of only the domain.

#### Remediation

Install a configuration profile with **PayloadType `com.apple.Safari`** and set **ShowFullURLInSmartSearchField** to `true`.

Framework mappings

- **CIS Controls v8**: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
- **NIST SP 800-53 Rev. 5**: CM-10 Software Usage Restrictions; SC-18 Mobile Code

Risk

High Profile Threat

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Safari Status Bar Is Shown](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#safari-status-bar-is-shown)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

**Finding:** Safari status bar is hidden.

Checks the Safari setting that shows the status bar revealing link destinations on hover.

This rule fails when `showStatusBar` is not `true` for a Safari user-settings object.

**Rationale:** The status bar reveals a link's true destination before the user clicks, exposing deceptive links.

**Impact:** Hovering a link shows its destination in the status bar.

#### Remediation

Install a configuration profile with **PayloadType `com.apple.Safari`** and set **ShowOverlayStatusBar** to `true`.

Framework mappings

- **CIS Controls v8**: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients
- **NIST SP 800-53 Rev. 5**: CM-10 Software Usage Restrictions; SC-18 Mobile Code

Risk

High Profile Threat

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Safari Warns When Visiting a Fraudulent Website](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#safari-warns-when-visiting-a-fraudulent-website)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.3

**Finding:** Safari fraudulent-website warning is disabled.

Checks the Safari per-user setting that warns before loading known phishing or malware sites.

This rule fails when `warnFraudulentWebsites` is not `true` for a Safari user-settings object.

**Rationale:** The warning is a first-line defense against phishing and drive-by malware sites.

**Impact:** Safari displays a warning interstitial for known fraudulent sites.

#### Remediation

Install a configuration profile with **PayloadType `com.apple.Safari`** and set **WarnAboutFraudulentWebsites** to `true`.

Framework mappings

- **CIS Controls v8**: 9.1 Ensure Use of Only Fully Supported Browsers and Email Clients; 9.3 Maintain and Enforce Network-Based URL Filters
- **NIST SP 800-53 Rev. 5**: CM-10 Software Usage Restrictions; SC-7 Boundary Protection; SC-18 Mobile Code
- **PCI DSS v4.0.1**: 1.2.6 Add security features that offset risk from active insecure services; 1.4.2 Permit untrusted-to-trusted inbound traffic only to authorized public services

Risk

High Profile Threat

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 6.4 Terminal

### [Ensure Terminal Secure Keyboard Entry Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/applications.html#terminal-secure-keyboard-entry-is-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 6.4

**Finding:** Terminal Secure Keyboard Entry is disabled.

Checks Terminal.app Secure Keyboard Entry, which blocks other apps from intercepting keystrokes.

This rule fails when `terminalSecureKeyboardEntry` is not `true` for a Terminal user-settings object.

**Rationale:** Without Secure Keyboard Entry, other processes can capture keystrokes (including passwords) typed in Terminal.

**Impact:** Other applications can no longer read keystrokes entered in Terminal.

#### Remediation

Install a configuration profile with **PayloadType `com.apple.Terminal`** and set **SecureKeyboardEntry** to `true`.

From the command line:

```sh
/usr/bin/defaults write -app Terminal SecureKeyboardEntry -bool true
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
