What breaks when macOS 27 hides netstat and ARP from apps
Published 2026-09-29
On macOS 27, two network tables are withheld from programs that an app starts. The commands still succeed and exit 0, but they print nothing. Run the same commands in Terminal and they work, so the only symptom is a monitoring tool that says everything is fine.
What we saw
netstat -an -p tcpandnetstat -an -p udpexit 0 with no output at all.netstat -anprints only the multipath and UNIX-domain socket sections. The TCP and UDP tables are simply missing.arp -a -nexits 0 with no output, andarp -n 192.168.1.1answers-- no entryfor a host that Terminal resolves.
This is not an app-sandbox denial. We reproduced it from an unsandboxed build, and nothing appears in the sandbox log. For ARP, unsigned, ad-hoc-signed and fully bundled test binaries all behave the same way.
Why it matters
Empty output fails in the direction that looks safe. A script that parses netstat for a listening port concludes the port is closed. A check that looks for an established VPN connection concludes the VPN is down. A rule that matches your router by its MAC address stops matching. In our own testing before we changed FrontierStack, this showed up as a VPN reported as disconnected during a live session, and as every port reported as not exposed.
What still works
Only those two tables are restricted. netstat -rn (routes) and netstat -bi (interface counters) still work, and so did every other probe we tried: ifconfig, route, scutil, sysctl, ps, df, diskutil, launchctl, dscl, dig, ping, curl, log and every form of lsof.
Replace netstat with lsof
lsof returns the same socket information and is not restricted. It needs no privileges for your own processes; run it with sudo to see every process.
# every open network socket
lsof -nP -i
# listening TCP ports
lsof -nP -iTCP -sTCP:LISTEN
# who is using a UDP port
lsof -nP -iUDP:1194ARP has no clean replacement yet
We have not found a fallback for the IPv4 ARP cache. The routing socket withholds the same entries, and ndp -an still lists IPv6 neighbours but is no substitute for IPv4. Access looks tied to the Local Network privacy permission, but that is not the whole rule: we have seen the table stay empty for an app with Local Network access switched on, while another app on the same Mac read it normally. We will update this post when we know more.
What to do
- Move scripts and monitoring checks that an app or agent runs from netstat over to lsof.
- Test commands from the process that really runs them, not from Terminal. A command that works in Terminal and returns nothing in your tool is the tell.
- Treat empty output as unknown, not as "nothing found". A MAC-address check should report that it cannot tell, rather than that there is no match.
What FrontierStack does
FrontierStack reads listening ports and open connections with lsof, and keeps netstat only as a fallback for older macOS. Where ARP matters (Device Discovery, Router & Network and Locations) it tells "no MAC cached" apart from "macOS will not say", shows the check as unknown instead of failed, and offers a card to grant Local Network access.
Run it from your Mac.
FrontierStack installs, monitors and secures services on this Mac and on linked servers.
Download FrontierStackApple notarized · Safe & secure · macOS 13 Ventura+
