What changed in macOS Tahoe 26.4? (Take 2)

It’s not very often we have the wisdom of hindsight and can go back to document changes made in macOS over six months ago. This brief article adds information on some of the more consequential changes made in macOS Tahoe 26.4, released on 24 March 2026. These are in addition to my original analysis, published here on the day of its public release.

Apple’s official documentation is confined to the following:

Additional new and changed features in macOS 26.4

Keychains

Login keychains used in macOS 26.4 or later are converted to use a protected entropy file in addition to the user password for decryption. Without their entropy files, backed up or copied login keychains are useless, as they can’t be unlocked. These are described in the final section added to TN3137 On Mac keychain APIs and implementations, published 1 November 2022 and updated on 24 September 2026. Note that Apple stresses the information given there doesn’t constitute part of the API, and is subject to change without warning.

Volume structure

Added a SIP-protected directory at /var/db/SystemKeys to contain keychain entropy files. This directory can only be accessed when SIP is turned off.

Added an empty directory pkg to the Data volume, which has a firmlink to /pkg that appears non-functional until macOS 27. This is described in my recent account.

Time Machine

Added the protected directory at /var/db/SystemKeys to backups of Data volumes, and protects them in backups.

Migration Assistant

When migrating from a backup using one-Mac migration, this now copies any required keychain entropy files to the /var/db/SystemKeys directory to enable those keychains to be unlocked. It may also perform similar copying of entropy files when required in two-Mac migration.

security command tool

The show-keychain-info command has a new option -s to display the salt for each file-based keychain. For those keychains that have an entropy file, the salt is the name of that file. This is explained and exemplified in TN3137 On Mac keychain APIs and implementations, but still hasn’t been added to man security.

I apologise for being six months late in listing these important changes. Is there anything else of significance that I haven’t mentioned?