The blog post about Catalina going around is an interesting case study in path-based filesystem sandboxing: https://lapcatsoftware.com/articles/macl.html
Last updated: Jan 24 2025 at 00:11 UTC