com.apple.quarantine Flags: Reading the Quarantine xattr
How to decode a com.apple.quarantine value: flag bits such as 0083 and 00c3, the hex timestamp, agent and UUID, with a source and confidence for each flag.
TL;DR. A com.apple.quarantine value has four fields, flags;time;agent;uuid, for example 0083;66f7c2a1;Safari;6E4C2B1A-.... The flags are a hexadecimal bit field that Apple does not document; open-source WebKit and Apple Security code name the important bits, and 0x0040 means the user approved the item through Gatekeeper. The time is Unix seconds in hex (UTC), the agent is the downloading app, and the UUID joins the file to its row in QuarantineEventsV2.
The value format
The quarantine attribute is an extended attribute named com.apple.quarantine. Its value is a short text string with four fields separated by semicolons:
0083;66f7c2a1;Safari;6E4C2B1A-...
| Field | Example | Meaning |
|---|---|---|
| flags | 0083 | Hexadecimal bit field, see the flag table |
| time | 66f7c2a1 | Unix seconds in hexadecimal, UTC |
| agent | Safari | Name of the app that wrote the file |
| uuid | 6E4C2B1A-... | Joins to LSQuarantineEventIdentifier; may be empty |
The flag bits, with sources and confidence
Apple does not document these flags publicly. The table says where each name and value comes from, so you can weigh your conclusions accordingly. More detail in the quarantine flags glossary entry.
| Bit | Name | Source | Confidence |
|---|---|---|---|
0x0001 | QTN_FLAG_DOWNLOAD | WebKit QuarantineSPI.h (open source) | High |
0x0002 | QTN_FLAG_SANDBOX | WebKit QuarantineSPI.h | High |
0x0004 | QTN_FLAG_HARD | WebKit QuarantineSPI.h; Apple Security policyengine.cpp treats such files as hard quarantined | High |
0x0040 | QTN_FLAG_USER_APPROVED (QTN_FLAG_ASSESSMENT_OK in Apple Security) | WebKit QuarantineSPI.h; policyengine.cpp sets it when the user overrides or approves via Gatekeeper | High |
0x0080 | QTN_FLAG_TRANSLOCATE | Name in Apple's libsecurity_translocate and copyfile sources; value from third-party re-declarations | Medium |
0x0100 | QTN_FLAG_DO_NOT_TRANSLOCATE | Same as above | Medium |
Any other bit, e.g. 0x0020 | Unknown | None | Reported as unknown |
A few notes on meaning. Apple's Security code treats hard-quarantined files, made by sandboxed sources without download privilege, as rejected for execution. App Translocation is what happens when a quarantined app is launched from an unexpected location: it runs from a randomized read-only mount, with paths under /private/var/folders/.../AppTranslocation/. And the 0x0040 value for "assessment OK / user approved" is consistent across the sources, which is why the user-approved flag is the most useful bit in an investigation.
Common values and how to read them
| Value | Bits | Reading |
|---|---|---|
0081 | 0x0080 + 0x0001 | Download, translocate bit |
0083 | 0x0080 + 0x0002 + 0x0001 | Download, sandbox, translocate bit |
0082 | 0x0080 + 0x0002 | Sandboxed app wrote the file, no download bit |
00c3 | 0x0080 + 0x0040 + 0x0002 + 0x0001 | As 0083, plus user approved |
00c1 | 0x0080 + 0x0040 + 0x0001 | As 0081, plus user approved |
0183 | 0x0100 + 0x0080 + 0x0002 + 0x0001 | As 0083, plus the do-not-translocate bit |
0086 | 0x0080 + 0x0004 + 0x0002 | Hard quarantine, sandbox, translocate bit |
The most telling pattern is a change on the same file: 0083 becoming 00c3 means the user approved it through Gatekeeper. If you only have one snapshot, 00c3 or 00c1 still shows approval happened at some point.
Other fields: time, agent, UUID
Time
The second field is Unix seconds, hexadecimal, UTC. Convert it on macOS with:
date -u -r $((16#66f7c2a1))
which prints Sat Sep 28 08:47:29 UTC 2024.
Agent and the \x20 escape
The agent is an app name, not a bundle identifier. Spaces are escaped as \x20 in the attribute, so Microsoft Word appears as Microsoft\x20Word. Unescape before you group by agent.
Zero time, empty agent, empty UUID
Values such as 0081;00000000;; exist: no time, no agent, no UUID. They were observed on a live macOS 26.6 system and are not suspicious in themselves; there is simply nothing to join.
Lower-case UUIDs
On the same system a few UUIDs were lower-case. Always compare UUIDs case-insensitively. An attribute UUID with no database row is also common (Safari downloads on that system had none in recent months), so treat it as a lead, not a finding.
How the attribute propagates
- Archive Utility applies the archive's quarantine value, UUID included, to every file it extracts. One database row can therefore match many files. Third-party unarchivers may not propagate it.
- Disk images: mounting a quarantined disk image marks its contents as quarantined.
- Copies within APFS or HFS+ keep extended attributes. On file systems without xattrs (exFAT, FAT, SMB shares) macOS writes AppleDouble
._namefiles that carry them. - Finder "Compress" ZIPs include
__MACOSX/._nameentries with the attributes.
How it is removed
xattr -d com.apple.quarantine file
xattr -c file
The first removes the quarantine attribute, the second removes all extended attributes. Neither touches the QuarantineEventsV2 database. A targeted xattr -d leaves other attributes in place, including the browser-set kMDItemWhereFroms, so a file with WhereFroms but no quarantine attribute suggests someone stripped it. See kMDItemWhereFroms vs quarantine.
Reading the attribute
xattr -p com.apple.quarantine file
xattr -l file
xattr -r -l -x ~/Downloads
xattr -p prints one attribute's value, xattr -l lists all attributes with their values, and xattr -r -l -x walks a folder and prints hex dumps, which keep the exact bytes (the recommended form for evidence). ls -l@ shows only attribute names and sizes, not the values. For the WhereFroms URLs through Spotlight, use mdls -name kMDItemWhereFroms file.
Quarantine Parser accepts all of these listings pasted into a text box, including find … -exec xattr -p … output, plus AppleDouble files, and joins each value to its database event.
What "approved" proves, and what it does not
The 0x0040 bit shows that the item went through a Gatekeeper approval. Because the attribute travels with copies, that approval did not necessarily happen on the Mac you are examining. The bit does not tell you when that happened, who clicked (a stolen session looks the same), or whether the program then ran successfully.
The absence of 0x0040 proves even less. Only executables, installers and apps go through the approval; a document can be opened many times without ever gaining that bit. For the rejected side of the story, see .LastGKReject as Gatekeeper evidence, and for the database side, QuarantineEventsV2 forensics. A cheat sheet lives at macforensics.app.
Frequently asked questions
What does 0083 mean in com.apple.quarantine?
Read bit by bit, 0083 is 0x0080 + 0x0002 + 0x0001: the translocate bit (value known from third-party re-declarations, medium confidence), the sandbox bit and the download bit. It is one of the most common values on downloaded files.
What does 00c3 mean?
00c3 is 0083 plus 0x0040, the user-approved bit. A file whose value changed from 0083 to 00c3 was approved by the user through Gatekeeper. Apple does not document the flags publicly; this reading comes from WebKit and Apple Security open-source code.
Does removing com.apple.quarantine delete the download record?
No. xattr -d com.apple.quarantine or xattr -c removes the attribute from the file only; the row in QuarantineEventsV2 stays. A file that keeps kMDItemWhereFroms but has no quarantine attribute deserves a closer look.
How do I convert the hex time in a quarantine value?
The second field is Unix seconds in hexadecimal, UTC. On macOS, date -u -r $((16#66f7c2a1)) prints Sat Sep 28 08:47:29 UTC 2024 for the value 66f7c2a1.