started · updated
macOS Tahoe 26.4 restricts manual login keychain copying
Starting with macOS Tahoe 26.4, Apple has implemented a change that prevents the manual copying of login keychain files between different Macs. While this change was not explicitly mentioned in release notes, testing has revealed that login keychain files copied to a new device can no longer be opened, even with the correct password.
The issue stems from the login keychain being tied to the original device's Secure Enclave, a dedicated security chip. Because the decryption keys are hardware-bound to the specific Secure Enclave of the original Mac, a copied file cannot be unlocked on a different machine. When a user attempts to open a copied keychain, macOS typically sets the file aside and automatically creates a new, empty login keychain.
This restriction does not affect users utilizing Migration Assistant, which correctly transfers keychain data, nor does it impact users restoring backups to the same original device via Time Machine. Additionally, user-created keychains that are not the primary login keychain remain functional across devices. This shift aligns with Apple's broader move toward the 'Data Protection Keychain' and the 'Passwords' app, which utilize iCloud Keychain for cross-device synchronization.
Entities
Apple · Secure Enclave · macOS