Malwarebytes is rolling out a new firewall feature for its Mac security suite that sits on top of Apple’s built-in protections and gives users more direct control over how their systems handle incoming network connections[1]. The feature, dubbed Malwarebytes Firewall, is being positioned as a way to make Apple’s application firewall easier to understand and tune, particularly for people regularly connecting their laptops to public or untrusted Wi‑Fi networks[1].
Every modern Mac ships with an application-layer firewall that can block unsolicited inbound connections and help shield the device from network access and denial-of-service attacks[3][7]. Apple’s documentation notes that the firewall can be configured in System Settings by navigating to Network and then Firewall, where users can toggle it on, choose to block all incoming connections, or automatically allow built-in and signed software to receive traffic[3][11][14]. The operating system also supports a “stealth” configuration that prevents the Mac from responding to certain network probes and port scans, making it harder to enumerate on shared networks[3][4].
Malwarebytes Firewall does not replace this native protection but instead exposes a simplified set of controls that adjust Apple’s firewall under the hood[1]. According to Malwarebytes, the new feature adds four main options: Stealth Mode, which makes a Mac harder to discover on public Wi‑Fi; Strict Mode, which pares access back to core services like web browsing and email while potentially breaking conveniences such as AirDrop or screen sharing; a “Trust Apple apps” setting that automatically allows traffic to first-party applications like FaceTime and Messages; and a “Trust verified downloaded apps” setting that permits incoming connections for user-approved, signed software such as videoconferencing and cloud storage clients[1].
Underneath these controls, macOS combines the user-facing Application Firewall with a lower-level packet filter derived from OpenBSD’s pf, giving the platform two separate layers of network enforcement[2][5]. Security practitioners note that Apple’s Application Firewall focuses on per-app inbound connections and does not filter outbound traffic, while the pf engine can enforce more traditional rule-based packet filtering at the cost of additional complexity[2][5][6]. That division has historically left many non-expert users either relying on default settings or turning to third-party tools to bridge the usability gap when they want tighter host-based controls on laptops they move between home, office and public networks[2][6].
The new Malwarebytes controls are aimed squarely at that gap by packaging common hardening options into plain-language modes users can toggle as their environment changes[1]. For example, a user might keep “Trust Apple apps” and “Trust verified downloaded apps” enabled on a trusted home network, then switch on Stealth Mode—or even Strict Mode—on hotel or airport Wi‑Fi to reduce their attack surface while still maintaining basic connectivity[1]. While the feature does not change the fundamental capabilities of macOS’s built-in firewall, it lowers the friction of using them correctly, which can matter in scenarios where attackers are scanning shared networks for exposed services to target for lateral movement or opportunistic compromise.
There is no new vulnerability or CVE associated with this release; instead, the security impact depends on whether users actually enable and tune the host firewall they already have. Apple continues to recommend keeping macOS updated and using the firewall to block unwanted connections, and administrators in managed environments can still push firewall payloads through mobile device management profiles for consistency across fleets[3][4]. For individual users, updating to the latest version of Malwarebytes for Mac to access the new firewall feature is one more way to bring often-overlooked host firewall settings into everyday security hygiene, rather than leaving them buried in a menu few people ever open[1].
References
- Your Mac already has a built-in firewall. Here’s how to get more from it
- macOS Built-in Firewall & Application Firewall (pf)
- Firewall security in macOS – Apple Support
- Firewall security in macOS
- How to Use the macOS Firewall (pf) to Restrict Network …
- Mac Firewall: Should You Turn It On or Off? – CoreLock
- Firewall security in macOS – Apple Support (IN)
- Change Firewall settings on Mac
- Block connections to your Mac with a firewall – Apple Support
