Home › Blog › What breaks when macOS 27 hides netstat and ARP from apps

What breaks when macOS 27 hides netstat and ARP from apps

Published 2026-09-29

On macOS 27, two network tables are withheld from programs that an app starts. The commands still succeed and exit 0, but they print nothing. Run the same commands in Terminal and they work, so the only symptom is a monitoring tool that says everything is fine.

What we saw

This is not an app-sandbox denial. We reproduced it from an unsandboxed build, and nothing appears in the sandbox log. For ARP, unsigned, ad-hoc-signed and fully bundled test binaries all behave the same way.

Why it matters

Empty output fails in the direction that looks safe. A script that parses netstat for a listening port concludes the port is closed. A check that looks for an established VPN connection concludes the VPN is down. A rule that matches your router by its MAC address stops matching. In our own testing before we changed FrontierStack, this showed up as a VPN reported as disconnected during a live session, and as every port reported as not exposed.

What still works

Only those two tables are restricted. netstat -rn (routes) and netstat -bi (interface counters) still work, and so did every other probe we tried: ifconfig, route, scutil, sysctl, ps, df, diskutil, launchctl, dscl, dig, ping, curl, log and every form of lsof.

Replace netstat with lsof

lsof returns the same socket information and is not restricted. It needs no privileges for your own processes; run it with sudo to see every process.

# every open network socket
lsof -nP -i

# listening TCP ports
lsof -nP -iTCP -sTCP:LISTEN

# who is using a UDP port
lsof -nP -iUDP:1194

ARP has no clean replacement yet

We have not found a fallback for the IPv4 ARP cache. The routing socket withholds the same entries, and ndp -an still lists IPv6 neighbours but is no substitute for IPv4. Access looks tied to the Local Network privacy permission, but that is not the whole rule: we have seen the table stay empty for an app with Local Network access switched on, while another app on the same Mac read it normally. We will update this post when we know more.

What to do

What FrontierStack does

FrontierStack reads listening ports and open connections with lsof, and keeps netstat only as a fallback for older macOS. Where ARP matters (Device Discovery, Router & Network and Locations) it tells "no MAC cached" apart from "macOS will not say", shows the check as unknown instead of failed, and offers a card to grant Local Network access.

Run it from your Mac.

FrontierStack installs, monitors and secures services on this Mac and on linked servers.

Download FrontierStack

Apple notarized · Safe & secure · macOS 13 Ventura+