Apple has added a security feature in macOS Tahoe 26.4 that warns users before potentially harmful commands are pasted and executed in Terminal, a change aimed at reducing ClickFix attacks on Macs.
KEY FACTS
- New warning macOS Tahoe 26.4 delays execution of risky pasted commands in Terminal.
- Targeted threat The feature appears designed to blunt ClickFix social engineering attacks.
- User alert The prompt says no damage has been done because execution was halted.
- Behavior unclear Apple has not published an official support document explaining how the warning is triggered.
ClickFix attacks try to trick users into pasting malicious commands into a command line interface, often under the guise of a fix or verification step. Because the user pastes the command, existing security measures can be bypassed.
The new prompt appears after users paste commands into Terminal, including cases reported when copying from Safari. It tells users that scammers often spread malicious instructions through different channels and warns that the command has been stopped.
Apple did not mention the feature in the macOS Tahoe 26.4 release notes. Reports from users on Reddit and X suggest the warning may only appear once per session and may depend on whether the pasted command is judged risky.
The report also noted that some users saw alerts for dangerous commands, while others said harmless commands did not trigger them.
WHY IT MATTERS
The change gives Mac users an extra warning before running commands that could damage a system or install malware. It also shows that Apple is trying to address a social engineering method that can bypass traditional protections when users act on instructions from untrusted sources.

