Skip to content

Glossary

App Translocation

macOS runs a quarantined app launched from an unexpected location from a randomized read-only mount under an AppTranslocation path.

App Translocation applies to quarantined apps launched from an unexpected location. Instead of running in place, the app runs from a randomized read-only mount, with paths under /private/var/folders/.../AppTranslocation/. When such a path shows up in other artifacts, it suggests a quarantined app, and the real location on disk has to be found elsewhere.

Two quarantine flags relate to it: QTN_FLAG_TRANSLOCATE and QTN_FLAG_DO_NOT_TRANSLOCATE. Their names appear in Apple's libsecurity_translocate and copyfile sources, while the values usually quoted, 0x0080 and 0x0100, come from third-party re-declarations and carry medium confidence. The commonly seen values 0081 and 0183 both include the 0x0080 bit. See com.apple.quarantine flags explained.