What is com.apple.Safari.SafeBrowsing.Service?
Last updated: 2026-07-31
com.apple.Safari.SafeBrowsing.Service is an Apple system launch agent that periodically updates databases used by Safari’s phishing and malware warnings. It can work while Safari is closed, and Apple does not confirm that it checks every page directly.
What it is
com.apple.Safari.SafeBrowsing.Service is an Apple system launch agent associated with Safari’s Safe Browsing framework. Its name looks like a bundle identifier because the launchd label, Mach-service name, and executable basename all use that form. The local executable’s code-signing identifier and the framework’s bundle identifier use the shorter com.apple.Safari.SafeBrowsing.
The clearest documented responsibility of com.apple.Safari.SafeBrowsing.Service comes from the man page bundled with macOS: it periodically updates the databases used by Safari Safe Browsing. Those databases support Safari’s warnings about websites suspected of phishing or distributing malware. The component is supplied by Apple and resides under /System/Library.
That documented database-updater role is narrower than some descriptions found online. Apple does not publicly confirm that com.apple.Safari.SafeBrowsing.Service performs a new online verdict request for every page visited or every warning displayed. Because the framework’s implementation is private, that stronger claim remains unverified.
Why it talks to the network
The confirmed network trigger for com.apple.Safari.SafeBrowsing.Service is a periodic background refresh of the Safe Browsing databases. This work can happen even when Safari is not open, so seeing a connection without an active Safari window does not by itself indicate unexpected activity. The documented workload is maintenance of the data Safari uses for its fraudulent-site protection.
Apple also describes network activity at the broader Safari feature level. Before visiting a website, Safari may send information calculated from the site’s address to Google Safe Browsing and Apple. Tencent Safe Browsing may also be used when the configured region is China mainland or Hong Kong. Apple says the actual website address is not shared with the Safe Browsing provider, although Google or Tencent may see and log the IP address making the connection.
There is an important boundary around that explanation: Apple does not establish that every feature-level request is sent directly by com.apple.Safari.SafeBrowsing.Service. Another Safari component could be involved. Periodic database updating is confirmed for this exact process; direct responsibility for every pre-visit Safe Browsing request is unverified.
How much traffic is normal
Apple publishes no normal byte range for com.apple.Safari.SafeBrowsing.Service, so there is no reliable MB figure to use as a universal baseline. A specific allowance would be guesswork and could be misleading across different machines or refresh events.
Its documented task suggests intermittent database-update bursts rather than a continuous stream of webpage, video, or file-download traffic. A database refresh can naturally transfer more data than an individual website check, so the size of one burst should not automatically be interpreted as evidence that browsing history or complete URLs are being uploaded.
The available documentation does not justify treating every amount as normal, either. Persistent high-volume transfers, traffic that behaves continuously, or downloads that repeatedly restart warrant diagnosis. Those patterns should be investigated rather than explained away as ordinary Safe Browsing activity without measurement.
Can you turn it off
The practical recommendation is to keep com.apple.Safari.SafeBrowsing.Service and Safari’s associated protection enabled. Apple’s supported user-facing control is:
Safari > Settings > Security > Warn when visiting a fraudulent website
Turning that setting off removes Safari’s warning for websites suspected of phishing or distributing malware. It is therefore a security tradeoff, not merely a way to silence an unfamiliar process in Activity Monitor.
Apple does not document this preference as a process-level kill switch. Disabling the warning does not guarantee that com.apple.Safari.SafeBrowsing.Service will never run. Its bundled man page says that the service has no configuration options and should not be run manually; force-unloading its LaunchAgent or deleting its system files is unsupported.
What people get wrong
1. “The bundle-like name means it is malware.” It does not. com.apple.Safari.SafeBrowsing.Service is an Apple-supplied platform component under /System/Library. Its launchd and executable names simply use identifier-style naming.
2. “It sends every complete URL or my entire browsing history to Google.” Apple says Safari may send information calculated from a website address, but the actual website address is not shared with the Safe Browsing provider. That does not make the connection anonymous: Google or Tencent may still see and log the connecting IP address.
3. “Every connection is a live check of the page currently open in Safari.” That has not been established. The bundled man page specifically documents periodic background database updates. Apple does not publicly assign every live Safe Browsing check to this exact process.
4. “It must never run after Safari closes, and if it does, Chrome must be using it.” Periodic background updates explain why com.apple.Safari.SafeBrowsing.Service can work without an open Safari window. Apple’s documentation does not establish that Chrome uses this service, so the process’s presence is not evidence of Chrome involvement.
5. “Disabling the LaunchAgent with launchctl or deleting its files is a safe optimization.” Apple does not support that approach. The documented service has no user configuration options and should not be invoked manually. Safari’s Fraudulent Website Warning preference is the supported control, with the consequence that disabling it removes phishing and malware warnings.
6. “It is responsible for Safari’s HTTPS certificate and ‘Not Secure’ warnings.” These are separate protections. Fraudulent Website Warning concerns sites reported as phishing or malware risks; certificate and connection-security warnings address different conditions.
Seeing what it actually used
The next step is to measure com.apple.Safari.SafeBrowsing.Service directly instead of assigning it an unsupported universal traffic allowance. Use Bytetally’s per-process statistics to see when transfers occur, how much data they use, and whether the pattern is intermittent or persistently high-volume. Repeated restarts or sustained heavy traffic are reasons to investigate further.
Related processes
Common questions
Is com.apple.Safari.SafeBrowsing.Service malware?
No. It is an Apple-supplied system component located under /System/Library and belongs to Safari’s Safe Browsing framework.
Why is com.apple.Safari.SafeBrowsing.Service running when Safari is closed?
Its documented job includes periodic background updates of the Safe Browsing databases, so an open Safari window is not required.
Does com.apple.Safari.SafeBrowsing.Service send my full URLs to Google?
Apple says Safari may send information calculated from an address, but not the actual website address, to the Safe Browsing provider. Google or Tencent may still see and log the connecting IP address.
Can I disable com.apple.Safari.SafeBrowsing.Service?
Safari provides a Fraudulent Website Warning setting, but turning it off removes phishing and malware-site warnings. Apple does not document that setting as a process-level kill switch.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account