What is com.apple.Safari.SafeBrowsing.Service on Mac?
Last updated: 2026-07-31
com.apple.Safari.SafeBrowsing.Service is an Apple-signed macOS service that updates the database behind Safari’s warnings for suspected phishing, malware, and other harmful sites. Its verified network activity is mainly periodic database updates, and keeping Safari’s fraudulent-site warning enabled is the safer default.
What it is
com.apple.Safari.SafeBrowsing.Service is an Apple-supplied background service included with macOS. The local manual page identifies its specific job: it periodically updates the database used by Safari Safe Browsing. That data allows Safari to warn before opening a site suspected of phishing, distributing malware, or presenting another known type of harm.
The distinction between this role and general-purpose security software matters. com.apple.Safari.SafeBrowsing.Service is not a complete antivirus product, and it does not protect every application, browser, or network connection on the Mac. Its documented purpose is tied to Safari’s fraudulent-website warning and the supporting Safe Browsing data.
The service is an Apple-signed system LaunchAgent under /System/Library, with components in the SafariSafeBrowsing private framework. Finding the process in a network monitor is therefore not evidence that adware or an unknown third-party program has installed itself. It is a normal macOS component, although its presence alone does not reveal how much data it transferred during a particular period.
Why it talks to the network
The verified reason com.apple.Safari.SafeBrowsing.Service connects in the background is to update the Safe Browsing database periodically. Its launchd configuration requires network availability and schedules the work as background activity. This means connections can appear even when no Safari window is visibly loading a page: the local protection data still needs occasional updates.
A second kind of activity may occur when Warn when visiting a fraudulent website is enabled in Safari. Before Safari visits a site, it may send information calculated from the site’s address to Google Safe Browsing and Apple. If the Mac’s system region is set to mainland China or Hong Kong, Tencent Safe Browsing may also be used.
Apple says the actual website address is not given to the Safe Browsing provider. That statement does not mean every request is necessarily relayed in a way that hides the user’s network address: Apple’s current privacy information says Google, and Tencent where applicable, may log the IP address when receiving the information.
Apple does not publicly identify the originating macOS process for every site-triggered check. Some or all of those queries might come from com.apple.Safari.SafeBrowsing.Service, Safari, or another WebKit-related process. Assigning all Safe Browsing lookups to this service would therefore go beyond the available evidence.
How much traffic is normal
There is no reliable official traffic range for com.apple.Safari.SafeBrowsing.Service, so a specific daily or monthly MB figure would be misleading. The manual page and launchd configuration establish only the general pattern: intermittent database updates, plus safety checks that may occur when needed.
The documented work does not involve transferring page bodies, images, videos, or other media on behalf of Safari. Under ordinary conditions, its traffic is therefore expected to be much smaller than traffic from image-heavy browsing, video streaming, or software downloads. That is a relative expectation, not a verified quota or fixed upper limit.
A first database setup, a database rebuild, or a large update could produce a higher temporary peak, but no verified size is available for those cases. A brief increase is not enough by itself to label the process malicious. The useful comparison is the process’s actual history on the specific Mac, because Apple has not published a universal baseline.
Can you turn it off
The supported user-facing control is:
Safari > Settings > Security > Warn when visiting a fraudulent website
The evidence supports keeping this protection enabled. Turning it off removes Safari’s corresponding warning for suspected phishing sites and may also remove Safe Browsing checks for known malware or other harmful websites. That is a direct security tradeoff, not merely a way to suppress a background process.
Apple does not provide a supported setting dedicated to disabling or uninstalling the com.apple.Safari.SafeBrowsing.Service LaunchAgent. The Safari setting controls the visible protection feature; Apple has not confirmed that switching it off guarantees the service will never launch or access the network again. It should not be treated as a reliable per-process network kill switch.
There is also no dependable evidence that disabling or deleting the service would make Safari substantially faster or save a large amount of data. Its verified background role is intermittent database maintenance, while disabling the Safari feature gives up warnings intended to catch phishing and other harmful destinations.
What people get wrong
- “
com.apple.Safari.SafeBrowsing.Serviceis malware, adware, or a suspicious third-party resident process.” It is an Apple-signed system LaunchAgent stored under/System/Library. Seeing the unfamiliar reverse-domain name in a process list does not change that identity.
- “It uploads every complete URL I visit, or my complete browsing history, to Google or Tencent.” That claim does not match Apple’s current statement. Apple says information calculated from the website address is sent and that the actual website address is not provided to the Safe Browsing provider.
- “Every Safe Browsing request is relayed through Apple, so Google can never see my IP address.” The current privacy information does not support that certainty. Apple explicitly says Google, and Tencent in applicable regions, may log an IP address when they receive the information.
- “Every Mac in every region connects to Tencent.” Apple limits this possibility to users whose system region is set to mainland China or Hong Kong. The available material does not support extending that statement to all regions.
- “Disabling or deleting
com.apple.Safari.SafeBrowsing.Servicewill significantly speed up Safari and save a large amount of traffic.” There is no reliable evidence for either benefit. The verified recurring task is intermittent database updating, while disabling the associated Safari protection sacrifices phishing and harmful-site warnings.
- “
com.apple.Safari.SafeBrowsing.Serviceis a complete system-wide antivirus.” Its scope is narrower. It supplies database updates and checking capabilities for Safari’s fraudulent and harmful-site warnings; it is not documented as protecting other browsers or all traffic on macOS.
Seeing what it actually used
The next step is to check com.apple.Safari.SafeBrowsing.Service in Bytetally’s per-process statistics over a representative period instead of comparing it with an invented universal MB limit. Look at whether usage is intermittent and whether a short peak differs from the process’s own normal history. Keep in mind that this measures the named process, while Apple has not confirmed that every site-triggered Safe Browsing query originates there.
Related processes
Common questions
Is com.apple.Safari.SafeBrowsing.Service malware?
No. It is an Apple-signed system LaunchAgent located under /System/Library.
Why is com.apple.Safari.SafeBrowsing.Service using the internet?
Its verified background task is periodically updating the database used by Safari Safe Browsing. Safari may also perform checks derived from website addresses when fraudulent-site warnings are enabled, but Apple does not document which process sends every such query.
Can I disable com.apple.Safari.SafeBrowsing.Service?
Apple provides no supported switch for disabling or uninstalling the LaunchAgent itself. Safari’s visible protection can be changed under Safari > Settings > Security > Warn when visiting a fraudulent website.
Does com.apple.Safari.SafeBrowsing.Service upload my browsing history?
Apple says Safe Browsing providers receive information calculated from a website address, not the actual website address. That does not support the claim that every full URL or a complete browsing history is uploaded.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account