The blog post about Catalina going around is an interesting case study in path-based filesystem sandboxing: https://lapcatsoftware.com/articles/macl.html
Last updated: Feb 24 2026 at 04:36 UTC