Security issues on macOS — page 2
Issues the maintainers labelled both platform:macos and area:security.
699 issues · 146 open · 553 resolved (79%) · first seen May 17, 2025
Is this getting better or worse?
This class of problem is still growing. 264 new reports in the last 90 days vs 138 in the 90 before — +91%. The open backlog peaked at 146 in 2026-08 and sits at 146 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
379 of these reports name the Claude Code build they were running, spanning 132 releases. Heaviest reporters:
- Claude Code v2.1.170
- Claude Code v2.1.198
- Claude Code v2.1.212
- Claude Code v2.1.201
- Claude Code v2.1.207
- Claude Code v2.1.12
- Claude Code v2.1.202
- Claude Code v2.0.76
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 36 days across 553 closures. Of the 553 closures with a recorded reason, 23% were closed as completed and 425 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
129 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG] VS CODE Extension no longer allows --dangerously-skip-permissions
- …ce with the newly updated Claude Code VSCode extension, the workaround with Ctrl+C and running 'claude --dangerously-skip-permissions' it does not work anymore. I've tried setting an alias in zshrc, but it does not work…
Found in the thread of #8539 · resolved - Skills/subagents do not inherit user-level permissions from settings.json
- …macOS 26.2 (25C56) - Settings file: ~/.claude/settings.json Workaround Select option 2 to create workspace-level permissions, but this defeats the purpose of user-level permissions. Impact Significantly degrades user exp…
Found in the description of #18950 · still open - [BUG] macOS sandbox blocks Security.framework TLS verification, breaking Go binaries (gh, terraform, etc.)
- …is script that patches the locally installed Claude Code to work around this bug: You would need to rerun this script every time Claude Code updates to re-apply the patch but it might help someone in the meantime.
Found in the thread of #23416 · still open - Skill allowed-tools doesn't grant permission for Bash commands
- …denied: The command attempted matches the pattern exactly: Workaround Adding directly to the global allow list works, but defeats the purpose of skill-scoped . Environment - Claude Code version: 2.0.75 - OS: macOS (Darw…
Found in the description of #14956 · still open - [BUG] permissions from user settings.json is NOT applied at project level
- …permissions should be a setting, not a mode. So I tried to workaround by adding permissions and it doesn't use them.
Found in the thread of #5140 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 101–200
Ranked by community engagement (reactions weighted over comments). Listing the top 300 of 699 matches; the statistics above cover all 699.
- deniedPaths bypassed by Bash tool — security policy not enforced uniformly across tools
- Sandbox filesystem allowlist doesn't resolve symlinks, causing "Operation not permitted" for Bash tools
- [Bug] rm -rf command deletes unintended parent directory contents
- ralph-wiggum plugin: Multi-line bash in command markdown files causes 'Command contains newlines' error
- [BUG] 5 Issues Identified With SubAgents
- [BUG] Permission Bypass Functionality Breaks When Adding ignorePatterns to Global Settings
- Incorrect Co-Author Attribution for Claude Code Commits to GitHub
- Remote Control should be opt-in, not on by default
- [BUG] Workspace trust dialog never appears in the VS Code extension (shown via CLI), so project-scope plugins / project .claude/settings.json are silently skipped
- MCP Plugin Security: Systemic Risks Identified Through Plugin Investigation
- Add a setting to opt out of the per-Read "consider whether it would be considered malware" system-reminder for trusted local repos
- [Bug] Auto mode bypasses manual permission prompt for dangerouslyDisableSandbox commands
- [BUG] Write tool bypasses sandbox filesystem write restrictions that Bash tool correctly enforces
- [버그] 서브에이전트(Explore)가 .env 파일 전체를 채팅에 출력 — 메모리 보안 지침이 서브에이전트에 적용 안 됨, 동일 사고 2회 반복
- CRITICAL: Claude attempts to delete home directory when cleaning up file named '~'
- [BUG] Bypassed global settings to read secret keys
- Bug: Sandbox half-broken — writes hit real filesystem, reads sandboxed — destroyed entire project
- [Bug] Update 1.1.7714 broke Claude Code desktop app — ccd-cli passes --allow-dangerously-skip-permissions as root + Hyper-V not initializing on Windows
- Malware campaign impersonating Claude Code install via Google Ads
- Permission bypass: Edit tool executed without approval when it should have been blocked
- Security: Deny rules can be bypassed by flag reordering/insertion
- [BUG] WebFetch allows huggingface.co without permission prompt, bypassing user settings
- Bug: PreToolUse Hooks Skipped - "Workspace Trust Not Accepted"
- [BUG] [Feature]
- [BUG] Permission settings unclear/inconsistent - security issues
- [BUG] Bash:* permission works inconsistently - randomly prompts for some commands
- [BUG]
- [BUG] Co-author Misattribution
- [BUG] globally defined `allowedTools` don't work the first time a path is opened
- Background auto-mode sessions execute Bash calls matching ask rules (and PreToolUse hook ask decisions) without any prompt (2.1.215)
- Permission rules are bypassed by semantically-equivalent command%2 0forms (`git -C`, `cd &&`, env prefixes)
- Scheduled wake-ups fire into wrong session when two sessions share a project dir
- [BUG] Organization-level policies bypassed when ANTHROPIC_BASE_URL is set, despite claude.ai OAuth authentication
- Sub-agent context isolation: parent MCP server registrations leak into sub-agent tool output
- No way to enforce approval on all file modifications
- [BUG] .aiignore glob patterns not enforced on Read and Edit tool calls
- [BUG] dangerouslyDisableSandbox bypasses sandbox without prompting in auto-allow mode
- [BUG] Claude ignoring .gitignore and reading secret keys in .env - .claudeignore .env by default
- PreToolUse hooks fail open when script file is missing; session deleted its own hook to bypass constraint
- Managed settings deny rules from Console not enforced (remote-settings.json)
- Claude Code drafts public bug reports containing sensitive project information without anonymising
- [Feature Request] Add bcr.bazel.build to allowed domains and support custom domain configuration
- [BUG] Permission prompts are erased from Claude's context after user approval, preventing debugging and causing misreporting
- [BUG] gradle being blocked by sandbox even though it's dir off of ~ is in the allow list
- Claude provided dangerous system command without adequate warning, causing permanent data loss
- [Feature Request] Stop resetting privacy settings to default on updates
- [BUG] VS Code Claude extension fails on diverse permission file configuration errors, but does not report them
- [Bug] File edit permissions not persisting across multiple edits
- [BUG] "Respect Git Ignore" setting doesn't prevent access to gitignored files via Bash tool
- [BUG] Inline command execution (!`cmd`) in slash commands fails with permission error
- [Bug] Terminal UI Corruption in Dangerously Skip Permissions Mode
- [BUG] "Yes, allow reading from `<dir>` from this project" no-ops
- File Reference Syntax Bypasses Configured Deny Permissions
- [BUG] `/security-review` command still missing on Claude Code 1.0.70
- [BUG] Sub-agents use tools without permission
- [BUG] Planning exists dangerously skip permissions mode
- [Bug] Fable 5 safeguards persistently escalate a benign health-corpus + security-governance project to Opus
- Agent tool subagents can access file paths outside approved permission boundaries
- [Bug] Unattributable prompt injection instruction detected in Claude Code session after plugin installation
- [BUG] Plugin sensitive userConfig not persisted to keychain/credentials.json/settings.json — values lost on Claude Code restart
- [BUG] Security: permissions.deny rules not working
- [BUG] Security: denyRead in sandbox not working
- [BUG] Selection injection from `ide` MCP server has no documented suppression mechanism, leaks env file contents to conversation transport
- [Bug] Claude Code exits with code 1 when inline --settings temp file in /tmp is owned by another user
- [BUG] False positive: macOS username ending in . triggers "suspicious Windows path pattern" on every write
- Bash tool calls not in allowlist executed without authorization prompt
- [BUG] [privacy] Claude Max account email auto-injected into LLM context with no opt-out
- [Bug] Security: Bash commands execute without user approval
- [BUG] Deny rules under permissions.deny not blocking file reads
- [BUG] Claude Code binary rejected by macOS 26 Gatekeeper — SIGKILL on 2nd concurrent instance
- Bash tool executed `brew install` without prompting user for approval
- [BUG] Buddy/Companion can inject ghost messages into the input stream as role: "user", impersonating the user
- [BUG] companyAnnoucements override
- [MODEL] Claude fabricates user consent after background task notification and edits sensitive file outside of any allowlist
- [BUG] `allowedMcpServers` in managed-settings.json can be bypassed via CLI flags
- Bash tool: newline characters in command string treated as spaces, causing rm -rf to delete unintended directories
- [BUG] Claude Code runs Bash(kill) in Plan Mode
- [BUG] Trust prompt appears every session when running Claude Code from home directory (~)
- [Feature Request] Support shell command substitution in MCP server env values
- [BUG]Critical Security: Accept All on code changes allows SSH/rm commands on remote servers without new permission prompt
- ralph-wiggum:ralph-loop skill fails with 'Command contains newlines' error
- [Bug] Wildcard patterns in allowlist not matching subshell commands in settings.json
- [Bug] Unsafe rm command execution deletes entire home directory
- [Feature Request] Add Bazel registry URLs to package manager URL list
- [Bug] Claude Code intercepts and continues external Claude SDK agent sessions
- [BUG] Claude will respect setting config to deny Read but not Write when file does not already exist
- [BUG] Scripts requires approval when run with tilde (~) path but not with absolute path
- [BUG] approved bash commands containing credentials are stored as is with plain text credentials in settings.local.json
- [Bug] Session transcripts leak secrets (GitHub PAT, API tokens) to persisted logs
- [FEATURE] Support wildcard/regex for `sandbox.network.allowUnixSockets` on macOS
- [bug] [area:agents] [platform:macos] Agent(isolation: "worktree") post-creation setup silently rewrites...
- [Bug] Security research false positives: Fable 5 flagging legitimate whitehat repo names
- Malware-policy system-reminder fires on every file read in user's own project, blocking approved plan execution
- Read tool results contain an injected <system-reminder> about "malware"
- Write deny rules not enforced via managed settings (.mobileconfig)
- [BUG] `excludedCommands` entries with `:*` suffix silently disable the entire sandbox for all Bash calls
- [Bug] Unintended file deletion: Claude deleted untracked file outside requested scope
- Plugin hooks that refresh OAuth tokens silently break authentication
- [BUG] Claude Code destroyed/pruned permanently Docker Images non related to the working project
- [BUG]Sandbox bypass: Claude Code writes outside sandbox after user denied Write permission