Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

The 2016 macOS controversy: Dropbox granting itself system access

September 2016

MediumStatus: ResolvedProduct: Desktop client (macOS)Year: 2016

Researchers revealed that Dropbox's Mac client used a user's admin password to directly edit macOS's protected TCC.db permissions database, inserting itself into the Accessibility list — a privacy/trust list that grants near-total control over the machine — without a clear, informed prompt.

What happened

In 2016 macOS developer Phil Stokes documented that Dropbox's Mac desktop client was appearing in the operating system's Accessibility permissions list without the user having knowingly granted it that access. Apps in the Accessibility list can observe and control the entire user interface — clicking menus and buttons, reading windows, and manipulating files — so it is one of the most powerful permissions on the system.

Further investigation showed how Dropbox got there: rather than going through Apple's intended permission flow, the client used the administrator password it requested at install time to directly modify the protected TCC.db database (located under /Library/Application Support/com.apple.TCC), the very file macOS uses to record which apps the user has authorized. By editing it directly, Dropbox effectively granted itself the access instead of asking for it through the proper, transparent mechanism. Even after a user manually removed Dropbox from the Accessibility list, it could reappear.

The behavior was characterized by critics as a 'dirty security hack' and a backdoor-like overreach, not because Dropbox was stealing data, but because it undermined the OS's own consent model and made the company's privileges opaque to the user. Apple subsequently tightened this area in macOS Sierra, requiring explicit per-app prompts for Accessibility access.

Impact

The episode struck at user trust in the most direct way: a service entrusted with users' files was quietly arrogating to itself the operating system's most sweeping permission, and doing so by subverting the very consent database meant to protect the user. It fueled a broader unease about how much control sync clients silently take over a machine, prompted security-conscious users to question and restrict Dropbox's footprint, and contributed to Apple hardening macOS permission prompts. While framed as integration convenience by Dropbox, it became a lasting reference point for cloud-client overreach.

Dropbox's Response / Official Position

Dropbox acknowledged the criticism, framing it as a communications failure rather than malicious behavior. A Dropbox desktop developer said the company asked for permissions once but had not adequately explained what it was doing or why, insisted Dropbox never saw or stored users' admin passwords, and said elevated access was used only where standard filesystem APIs were insufficient (for badge and integration features). The company apologized for the confusion and said it was working with Apple to remove the need for such permissions.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Across multiple years, attackers have built convincing fake Dropbox login pages — reached via PDF lures and redirect chains through trusted cloud storage — to harvest victims' real business email and Dropbox credentials.

Security Incidents & Data BreachesAccount Lockouts & Support Failures
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's own status page logged eleven separate incidents between January and September 2026 — mostly brief, but including a roughly 93-hour shared-content-download degradation in June and an 11-hour, 46-minute Dropbox Protect failure in August.

Reliability & Data LossCurrent / Ongoing Issues (2024–2026)
Read documentation