Silently updated security data files in Golden Gate

Each of the main security services in macOS such as XProtect relies on data normally stored in separate files on the Data volume so they can be updated directly outside full macOS system updates. Those are released silently by Apple, unannounced, and you aren’t even notified when they’ve been updated.

Currently, the service most frequently updated is XProtect, the collection of rules for the detection of known malware when apps are scanned on demand. Sequoia changed the way that XProtect’s data is updated, and it’s now intended to occur over a connection to iCloud rather than through Software Update, while its companion XProtect Remediator continues to rely on the latter not iCloud.

This article details each of the main security data files found in macOS 27 Golden Gate, together with others involved in related system functions. Several other bundles that formerly had roles in security have now been emptied, left frozen in time, or removed completely. As Apple doesn’t document any of them beyond mentioning their existence and simplified role, the information given here is the best that I can find currently.

Main Security Data

XProtectPlistConfigData and XProtectCloudKitUpdate
These are whitelists, blacklists and rules used by XProtect. Since Sequoia, two different locations are used: the primary is at /var/protected/xprotect/XProtect.bundle in the Data volume; the secondary is also in the Data volume at the traditional location of /Library/Apple/System/Library/CoreServices/XProtect.bundle, and can used as a fallback when there’s no bundle at the primary location. While all versions of macOS can still obtain XProtectPlistConfigData updates through Software Update, Golden Gate is also intended to update the primary bundle with XProtectCloudKitUpdate delivered via a CloudKit connection to iCloud. This is routinely updated most weeks, at about the same time as updates for previous versions of macOS. You may be able to force an update using the command sudo xprotect update in Terminal, if a more recent version is available.

XProtectPayloads, alias XProtect.app and XProtect Remediator
This contains a suite of specialised malware detection and remediation tools, in the app bundle XProtect.app in the Data volume at /Library/Apple/System/Library/CoreServices. This was introduced in macOS 12.3, then version 62 was pushed to Catalina and later on 17 June 2022. Executables include a replacement for MRT (below), and a suite of scanners for specific malware types. My free XProCheck inspects its reports for malware detection and remediation. This is normally updated every few months using Software Update or a substitute.

Bastion
This provides rules and exceptions for XProtect Behaviour Service. First introduced in Ventura, this service monitors for and logs processes that access sensitive locations such as folders containing browser data. This doesn’t block behaviours, only records them in its database at /var/protected/xprotect/XPdb, and reports them to Apple as security intelligence. Bastion rules are defined in bastion.sb and BastionMeta.plist inside /Library/Apple/System/Library/CoreServices/XProtect.app, and are updated irregularly.

AppleKextExcludeList
Latest version: 22.0.0, 3 September 2026 (27.0 release).
This is a huge list of kernel extensions that are to be treated as exceptions to Golden Gate’s security rules, and is stored in the Data volume in /Library/Apple/System/Library/Extensions/AppleKextExcludeList.kext, at Contents/Resources/ExceptionLists.plist. At one time, this was a blacklist of kexts to block, but in Mojave 10.14.5 that changed, and it has since been a list of over 18,000 kexts that are given exceptional treatment, as explained here. However, this doesn’t appear to apply to Apple silicon Macs, as they have their own more stringent rules about which kexts to allow and which to block. Although this list is expected to go away at some time in the future, it remains in macOS 27.0.

Others

IncompatibleAppsList
Latest version: 270.203 (27.0 release).
This is a bundle in the Data volume at /Library/Apple/Library/Bundles/IncompatibleAppsList.bundle which contains IncompatibleAppsList.plist, listing many known incompatible versions of third-party products, including Flash Player. Updates are normally delivered in a macOS update, with a new version for each major version of macOS.

Vestigial Data

MRTConfigData
Last version: 1.93, 14 July 2022.
This was Apple’s Malware Removal Tool stored in the Data volume at Library/Apple/System/Library/CoreServices/MRT.app, to remove any malware that macOS detected. This has now been replaced by the XProtectRemediatorMRTv3 executable module in XProtect Remediator, and may disappear in future versions of macOS. It isn’t installed as part of macOS, but later as a security data update.

Gatekeeper Configuration Data (GK Opaque)
Latest version: 94.
This is an SQLite database in the Data volume in /private/var/db/gkopaque.bundle/Contents/Resources/gkopaque.db and may have been used to provide whitelists for Gatekeeper’s security system, which checks the code signatures of apps. All indications are that this database is no longer used.

Gatekeeper Compatibility Data (GKE)
Latest version: 1.0, 2 October 2019.
This is a bundle apparently installed at /private/var/db/gke.bundle, and has nothing to do with Google Kubernetes Engine. It contains two substantial files. gke.auth is believed to contain data for checking signed disk images, and seems to have remained largely unchanged since Sierra. gk.db was new in Catalina and hasn’t changed since then. Although this is recorded as being downloaded and installed in macOS 27.0, no trace of it is to be found in that location, suggesting that it’s removed automatically, ingested or dispersed elsewhere.

Last updated: 27 September 2026.