The blog post about Catalina going around is an interesting case study in path-based filesystem sandboxing: https://lapcatsoftware.com/articles/macl.html
Last updated: May 03 2026 at 23:15 UTC