Why is SubmitDiagInfo using the network on my Mac?

Last updated: 2026-07-31

SubmitDiagInfo is an Apple-signed macOS process that handles diagnostic, crash, and usage reports you have agreed to share. Its presence does not prove an upload is happening, because it also queues reports and removes old diagnostic information.

What it is

SubmitDiagInfo is a background system process included with macOS and signed by Apple. Its executable is located at /System/Library/CoreServices/SubmitDiagInfo, while com.apple.SubmitDiagInfo is both its code-signing identifier and its launchd label. Calling that identifier an app bundle ID is not strictly precise because the executable does not have an attached Info.plist.

The process handles diagnostic, crash, system-event, and usage reports that qualify for submission and have not yet been sent. It does more than transmit data: it also checks and queues reports, and removes diagnostic information that was generated more than a month ago and is no longer needed.

For that reason, seeing SubmitDiagInfo in Activity Monitor does not by itself mean your Mac is uploading anything. The process can be active while examining a queue or performing local cleanup, even when there is no network transfer underway.

Why it talks to the network

SubmitDiagInfo can contact Apple's diagnostic and analytics receiving services when Share Mac Analytics is enabled and eligible reports are waiting to be sent. Automatic sharing requires user consent.

Apple specifically lists several events that can lead to information being sent automatically: an app quitting unexpectedly, the user force-quitting an app, and a system error that causes or requires the Mac to restart. Other system events and usage information covered by the sharing permission may also be submitted.

Reports are not necessarily transmitted when they are created. If the Mac is offline, they can remain queued and be sent after an internet connection becomes available again. Related analytics information may also be sent when the user actively chooses to report a problem.

If Share with App Developers is enabled separately, Apple may provide developers with a relevant subset of non-personally identifying analytics data. There is no evidence that SubmitDiagInfo itself connects directly to third-party servers. The exact list of hosts used at runtime has not been verified, and URL strings found inside the executable do not establish which endpoint a current submission actually uses.

How much traffic is normal

Normal traffic can range from zero to a short batch of uploads after one or more reportable events. Zero is expected when analytics sharing has not been authorized or when there are no reports waiting to be sent.

Apple has not published a reliable typical byte range or a maximum size for SubmitDiagInfo traffic. There is therefore no supported MB figure that can be used as a universal threshold. The amount depends on how many reports are pending and what those reports contain.

Its documented pattern is closer to occasional log submission than to a continuous audio, video, or cloud-storage stream. A burst after a crash, forced app exit, system error, period without connectivity, or manual problem report can fit that pattern. Periodic appearances of the process do not establish periodic uploads, because actual transmission still depends on consent, a pending report, and network availability.

Can you turn it off

Yes—but the supported control is for analytics sharing, not for deleting or forcibly disabling the system process.

Go to Apple menu > System Settings > Privacy & Security > Analytics & Improvements, then turn off Share Mac Analytics. If you also do not want Apple to share the relevant analytics subset with app developers, turn off Share with App Developers as well.

After Share Mac Analytics is disabled, the Mac stops automatically providing Apple with its crash, diagnostic, system-event, and usage analytics. Those reports consequently no longer contribute data to the related Apple quality-improvement work.

This setting does not prevent macOS from generating or displaying diagnostic reports locally. They can still be viewed under Mac Analytics Data in Console. It also does not guarantee that SubmitDiagInfo will never run again, because local report cleanup remains one of its responsibilities. A later decision to submit a problem report manually is a separate, explicit action.

A universal initial default for the sharing setting on modern macOS has not been verified. The actual state may reflect choices made during initial setup or a device-management policy, so it is better to inspect the current setting than to assume it is on or off.

What people get wrong

Seeing what it actually used

The next step is to check measured per-process traffic instead of inferring it from Activity Monitor presence alone. In Bytetally, look up SubmitDiagInfo in the per-process statistics and compare its actual usage with the times when crashes, restarts, reconnection, or manual reporting occurred. That shows whether it transferred nothing, produced a short batch, or followed a pattern that deserves closer examination.

Related processes

Common questions

Is SubmitDiagInfo malware?

No. Its system path, Apple code signature, and launchd label identify it as a built-in macOS component.

Why is SubmitDiagInfo connecting to the internet?

When Share Mac Analytics is enabled and eligible reports are waiting, it connects to Apple's diagnostic and analytics receiving services.

Can I disable SubmitDiagInfo?

You can turn off Share Mac Analytics in System Settings. This stops automatic sharing, but the process may still run for local cleanup.

Does SubmitDiagInfo upload my personal files?

There is no evidence that it uploads arbitrary personal files or browsing content. Submitted reports may still contain device and software-environment metadata.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account