← Back to context

Comment by bigyabai

16 hours ago

> it doesn't have any kind of proper desktop sandboxing architecture that really works.

Bubblewrap works.

Bubblewrap is a less powerful version of sandbox-exec, but the macOS architecture is much larger than just that. In effect macOS runs everything under bubblewrap, in such a way that users don't notice but apps are meaningfully sandboxed and root exploits barely matter.