Why is com.apple.WeatherKitService using my network?
Last updated: 2026-07-31
com.apple.WeatherKitService is an Apple-supplied, on-demand XPC service used by older macOS weather features in Calendar and Notification Center. Its traffic should normally be low and intermittent, and Apple provides no supported switch for disabling the service itself.
What it is
com.apple.WeatherKitService is a sandboxed XPC weather-query service supplied with older versions of macOS. It runs on demand rather than remaining active permanently, and it can exit after it has been idle. Historical process samples show it being invoked by CalendarAgent, Calendar, and NotificationCenter.
Its verified role is narrow. It retrieved weather information for older Notification Center weather widgets and for Calendar events that contained a recognizable location and needed weather details. Whether the process appears at all therefore depends on the macOS components present on that particular system and whether one of those features has called it.
The name can be misleading because Apple also uses WeatherKit for a modern developer framework. com.apple.WeatherKitService is not that modern WeatherKit service. It should also not be treated as a general label for every connection made by the current Weather app or by third-party weather applications. Current macOS weather components can use different service identifiers, and some macOS installations no longer contain this particular XPC service.
Why it talks to the network
The verified network triggers fall into two categories. One is a refresh by the older Notification Center weather widget. The other occurs when Calendar processes an event with a recognizable location and needs weather information for that event. In either case, com.apple.WeatherKitService contacts a weather data provider through an HTTPS API to retrieve the requested structured weather data.
Apple has not published an endpoint list for this private service. A historical observation from an older system recorded a connection to api.wunderground.com, but that observation does not establish a permanent endpoint, a universal provider, or behavior shared by every system release and region. Weather suppliers may change between system versions.
For that reason, it is not verified that com.apple.WeatherKitService always talks to Yahoo, always uses Weather Underground, or sends all requests to the current Apple Weather infrastructure. A fixed-domain explanation goes beyond the available evidence. The supported conclusion is simply that the service queried a weather data provider when one of its older Calendar or Notification Center callers requested weather information.
How much traffic is normal
Normal traffic from com.apple.WeatherKitService should be low to very low. Its expected activity consists of small, intermittent requests for structured weather information. That should ordinarily be far below the traffic generated by video or audio streaming, cloud-drive synchronization, or a system update.
There is no verified number of megabytes that can be presented as a normal allowance. Apple has not published the process’s byte usage, refresh schedule, or a reliable traffic range. Claims that it downloads a fixed amount or refreshes at an exact interval generally lack a reproducible system version, measurement window, and method.
This means the expected scale can be described qualitatively, but not as a trustworthy numeric threshold. Sustained high-volume transfers should not be assumed to be a normal characteristic of com.apple.WeatherKitService. If a monitor attributes substantial traffic to the name, the useful next step is to measure that specific Mac rather than compare it with an unsupported fixed figure from another system.
Can you turn it off
Apple does not provide a System Settings switch for disabling com.apple.WeatherKitService. There is therefore no supported settings path to follow. The appropriate default is to leave the system component in place.
Force-quitting the process is not a lasting way to stop its network access. It is an on-demand XPC service, so a caller can start it again when weather information is needed. Deleting the service, uninstalling system files, removing its container, or blocking it indefinitely can cause weather information to stop appearing in the older Notification Center widget or in Calendar events.
Location permission is a separate control. Turning off Weather’s access to the current location does not disable com.apple.WeatherKitService and does not guarantee that all weather requests will stop. A saved place or the location attached to a Calendar event can still support a query that does not require the Mac’s current position.
If a macOS installation no longer contains this XPC component, there is nothing to disable or manage. Its absence should not be confused with a successfully applied switch; newer weather-related components can have different service identifiers.
What people get wrong
- “The long name means it could be malware.” It does not. On the older macOS systems that contain it,
com.apple.WeatherKitServiceis an Apple-supplied XPC component. The process name alone is not evidence that it belongs to third-party software.
- “It is the modern WeatherKit service.” The older private XPC service and Apple’s modern developer-facing WeatherKit framework are not the same thing.
com.apple.WeatherKitServicealso does not account for all network activity from the current Weather app or from third-party weather applications. Current system components can use other identifiers.
- “Ending it or deleting its container is a reliable network optimization.” An on-demand XPC service may start again when Calendar or Notification Center requests it. Removing system components or their data can instead break the older weather display in those features, without providing a supported long-term control.
- “Disabling Weather location permission turns the service off.” Location permission controls access to the current position; it is not a service-level off switch. Weather queries based on a saved location or a recognizable place in a Calendar event may not need the current location.
- “It always connects to Yahoo, Weather Underground, or one fixed domain.” Apple has not published a stable endpoint list for this private service. The historical Weather Underground observation applies to an older system, while providers and endpoints may differ by system version or region. Assigning every connection to one named supplier is not verified.
- “It normally consumes a large, predictable amount of bandwidth.” There is no reliable basis for that conclusion. Expected traffic is small and intermittent, but Apple provides no fixed byte count or refresh interval. Online figures presented as an exact number of megabytes or a fixed schedule are not dependable unless they include a reproducible system version, time window, and measurement method.
Seeing what it actually used
If the practical question is how much com.apple.WeatherKitService used on your Mac, measure the process instead of relying on an unverified universal figure. In Bytetally, check the per-process statistics for the exact name com.apple.WeatherKitService. That gives you the locally observed amount without assuming a fixed provider, refresh interval, or normal megabyte total.
Related processes
Common questions
Is com.apple.WeatherKitService malware?
No. On the older macOS releases that include it, com.apple.WeatherKitService is an Apple-supplied XPC component.
Why is com.apple.WeatherKitService connecting to the internet?
Verified triggers include refreshes by the older Notification Center weather widget and Calendar events with recognizable locations that need weather information.
Can I disable com.apple.WeatherKitService?
Apple provides no system setting that disables this XPC service. Ending or blocking it can disrupt older Calendar or Notification Center weather features, and the service may start again on demand.
How much data should com.apple.WeatherKitService use?
Normal traffic should be low to very low, but Apple publishes no byte totals, refresh interval, or reliable traffic range for this process.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account