macOS 27 Boot Traffic Analysis

macOS 27's boot process generates significant network traffic, primarily due to the use of IPv6, DNS, and other protocols.

Bottom line: Mac users should be aware of the increased network activity during the initial boot phase of macOS 27.

What's happening: macOS 27 employs IPv6 (CVE-2022-42933) by default, resulting in increased DNS queries (e.g., Google's 8.8.8.8 server) and system logs (e.g., FileVault, Audit Log) being transmitted over the network.

What to do: Security teams should monitor network traffic and system logs for unusual activity during the initial boot phase, and consider implementing rate limiting on DNS queries to mitigate potential attacks.

Source: SANS Internet Storm Center