Skip to content

com.apple.quarantine Flags: Reading the Quarantine xattr

How to decode a com.apple.quarantine value: flag bits such as 0083 and 00c3, the hex timestamp, agent and UUID, with a source and confidence for each flag.

Published on 6 min read

TL;DR. A com.apple.quarantine value has four fields, flags;time;agent;uuid, for example 0083;66f7c2a1;Safari;6E4C2B1A-.... The flags are a hexadecimal bit field that Apple does not document; open-source WebKit and Apple Security code name the important bits, and 0x0040 means the user approved the item through Gatekeeper. The time is Unix seconds in hex (UTC), the agent is the downloading app, and the UUID joins the file to its row in QuarantineEventsV2.

The value format

The quarantine attribute is an extended attribute named com.apple.quarantine. Its value is a short text string with four fields separated by semicolons:

0083;66f7c2a1;Safari;6E4C2B1A-...
FieldExampleMeaning
flags0083Hexadecimal bit field, see the flag table
time66f7c2a1Unix seconds in hexadecimal, UTC
agentSafariName of the app that wrote the file
uuid6E4C2B1A-...Joins to LSQuarantineEventIdentifier; may be empty

The flag bits, with sources and confidence

Apple does not document these flags publicly. The table says where each name and value comes from, so you can weigh your conclusions accordingly. More detail in the quarantine flags glossary entry.

BitNameSourceConfidence
0x0001QTN_FLAG_DOWNLOADWebKit QuarantineSPI.h (open source)High
0x0002QTN_FLAG_SANDBOXWebKit QuarantineSPI.hHigh
0x0004QTN_FLAG_HARDWebKit QuarantineSPI.h; Apple Security policyengine.cpp treats such files as hard quarantinedHigh
0x0040QTN_FLAG_USER_APPROVED (QTN_FLAG_ASSESSMENT_OK in Apple Security)WebKit QuarantineSPI.h; policyengine.cpp sets it when the user overrides or approves via GatekeeperHigh
0x0080QTN_FLAG_TRANSLOCATEName in Apple's libsecurity_translocate and copyfile sources; value from third-party re-declarationsMedium
0x0100QTN_FLAG_DO_NOT_TRANSLOCATESame as aboveMedium
Any other bit, e.g. 0x0020UnknownNoneReported as unknown

A few notes on meaning. Apple's Security code treats hard-quarantined files, made by sandboxed sources without download privilege, as rejected for execution. App Translocation is what happens when a quarantined app is launched from an unexpected location: it runs from a randomized read-only mount, with paths under /private/var/folders/.../AppTranslocation/. And the 0x0040 value for "assessment OK / user approved" is consistent across the sources, which is why the user-approved flag is the most useful bit in an investigation.

Common values and how to read them

ValueBitsReading
00810x0080 + 0x0001Download, translocate bit
00830x0080 + 0x0002 + 0x0001Download, sandbox, translocate bit
00820x0080 + 0x0002Sandboxed app wrote the file, no download bit
00c30x0080 + 0x0040 + 0x0002 + 0x0001As 0083, plus user approved
00c10x0080 + 0x0040 + 0x0001As 0081, plus user approved
01830x0100 + 0x0080 + 0x0002 + 0x0001As 0083, plus the do-not-translocate bit
00860x0080 + 0x0004 + 0x0002Hard quarantine, sandbox, translocate bit

The most telling pattern is a change on the same file: 0083 becoming 00c3 means the user approved it through Gatekeeper. If you only have one snapshot, 00c3 or 00c1 still shows approval happened at some point.

Other fields: time, agent, UUID

Time

The second field is Unix seconds, hexadecimal, UTC. Convert it on macOS with:

date -u -r $((16#66f7c2a1))

which prints Sat Sep 28 08:47:29 UTC 2024.

Agent and the \x20 escape

The agent is an app name, not a bundle identifier. Spaces are escaped as \x20 in the attribute, so Microsoft Word appears as Microsoft\x20Word. Unescape before you group by agent.

Zero time, empty agent, empty UUID

Values such as 0081;00000000;; exist: no time, no agent, no UUID. They were observed on a live macOS 26.6 system and are not suspicious in themselves; there is simply nothing to join.

Lower-case UUIDs

On the same system a few UUIDs were lower-case. Always compare UUIDs case-insensitively. An attribute UUID with no database row is also common (Safari downloads on that system had none in recent months), so treat it as a lead, not a finding.

How the attribute propagates

  • Archive Utility applies the archive's quarantine value, UUID included, to every file it extracts. One database row can therefore match many files. Third-party unarchivers may not propagate it.
  • Disk images: mounting a quarantined disk image marks its contents as quarantined.
  • Copies within APFS or HFS+ keep extended attributes. On file systems without xattrs (exFAT, FAT, SMB shares) macOS writes AppleDouble ._name files that carry them.
  • Finder "Compress" ZIPs include __MACOSX/._name entries with the attributes.

How it is removed

xattr -d com.apple.quarantine file
xattr -c file

The first removes the quarantine attribute, the second removes all extended attributes. Neither touches the QuarantineEventsV2 database. A targeted xattr -d leaves other attributes in place, including the browser-set kMDItemWhereFroms, so a file with WhereFroms but no quarantine attribute suggests someone stripped it. See kMDItemWhereFroms vs quarantine.

Reading the attribute

xattr -p com.apple.quarantine file
xattr -l file
xattr -r -l -x ~/Downloads

xattr -p prints one attribute's value, xattr -l lists all attributes with their values, and xattr -r -l -x walks a folder and prints hex dumps, which keep the exact bytes (the recommended form for evidence). ls -l@ shows only attribute names and sizes, not the values. For the WhereFroms URLs through Spotlight, use mdls -name kMDItemWhereFroms file.

Quarantine Parser accepts all of these listings pasted into a text box, including find … -exec xattr -p … output, plus AppleDouble files, and joins each value to its database event.

What "approved" proves, and what it does not

The 0x0040 bit shows that the item went through a Gatekeeper approval. Because the attribute travels with copies, that approval did not necessarily happen on the Mac you are examining. The bit does not tell you when that happened, who clicked (a stolen session looks the same), or whether the program then ran successfully.

The absence of 0x0040 proves even less. Only executables, installers and apps go through the approval; a document can be opened many times without ever gaining that bit. For the rejected side of the story, see .LastGKReject as Gatekeeper evidence, and for the database side, QuarantineEventsV2 forensics. A cheat sheet lives at macforensics.app.

Frequently asked questions

What does 0083 mean in com.apple.quarantine?

Read bit by bit, 0083 is 0x0080 + 0x0002 + 0x0001: the translocate bit (value known from third-party re-declarations, medium confidence), the sandbox bit and the download bit. It is one of the most common values on downloaded files.

What does 00c3 mean?

00c3 is 0083 plus 0x0040, the user-approved bit. A file whose value changed from 0083 to 00c3 was approved by the user through Gatekeeper. Apple does not document the flags publicly; this reading comes from WebKit and Apple Security open-source code.

Does removing com.apple.quarantine delete the download record?

No. xattr -d com.apple.quarantine or xattr -c removes the attribute from the file only; the row in QuarantineEventsV2 stays. A file that keeps kMDItemWhereFroms but has no quarantine attribute deserves a closer look.

How do I convert the hex time in a quarantine value?

The second field is Unix seconds in hexadecimal, UTC. On macOS, date -u -r $((16#66f7c2a1)) prints Sat Sep 28 08:47:29 UTC 2024 for the value 66f7c2a1.

Related articles