Do You Need Antivirus on a Mac
Short answer
For most people, no permanent antivirus is needed. macOS runs Gatekeeper, XProtect and the Malware Removal Tool silently, and they cover the realistic threats. Keep Malwarebytes free installed as an on-demand scanner for the adware and browser hijackers that do get through, and run it only when something seems wrong.
On this page
Macs are not immune to malware, and anyone who tells you otherwise has not looked at what circulates. Macs are, however, protected by three layers that run automatically and that most owners have never heard of, because none of them has a window, an icon or a notification.
Once you know what those layers do, the question becomes much narrower: is there a gap worth filling, and is it worth filling with a subscription. The answers are yes and no, in that order.
The three layers already running
Gatekeeper checks an application before it is allowed to run for the first time. It verifies the app is signed by an identified developer and has been notarised by Apple, which means Apple’s automated systems scanned it for known malware. An unsigned application does not launch with a double-click; you have to go into System Settings and override it deliberately.
That override is the key detail. Most Mac malware does not defeat Gatekeeper. It persuades the user to defeat it, usually with on-screen instructions presented as a routine installation step.
XProtect is a signature-based scanner inside macOS. It checks applications against Apple’s list of known malware families at launch, and its definitions update in the background separately from system updates. No interface, no scan button, no reassuring green tick.
The Malware Removal Tool removes known malware already present, and runs during updates and at intervals, silently.
Alongside those sit System Integrity Protection, which stops even an administrator from modifying protected system files, and the app sandbox, which limits what a given application can reach. The result is an operating system that is genuinely hard to compromise without the owner’s cooperation.
What actually gets through
The gap is not in the technology. It is in the step where someone agrees.
| Threat | Does macOS stop it? | How it arrives |
|---|---|---|
| Adware and browser hijackers | Partly | Bundled with a download |
| Fake “Mac cleaner” applications | No | Pop-up adverts, search ads |
| Malicious browser extensions | No | Installed from the web store |
| Credential-stealing malware | Often | Cracked software, fake installers |
| Phishing pages | No | Email and messages |
| Ransomware | Usually | Rare on macOS |
Two rows carry the weight. Browser extensions are installed by the user with explicit permission, so no operating system protection applies, and they can read and change every page you visit. Fake cleaner applications are frequently signed and notarised, because being a nuisance is not the same as being malware by Apple’s definition.
Phishing is in the table as a reminder that the single most common way a Mac owner loses something valuable involves no malware at all. An antivirus product is not part of that fight, which is why recognising a phishing attack is a better use of an hour than comparing Mac security suites.
When a scanner is worth having
Keep Malwarebytes free installed, run it on demand. The free version does not install permanent real-time protection, which is the right trade. It is particularly good at the adware and unwanted-program categories that Apple’s own tooling treats conservatively. Run it when the browser starts behaving oddly, after installing something you later doubted, or once or twice a year.
Download it from the vendor’s own site. Searching for Mac antivirus and clicking an advert is how people end up installing exactly the category of software they were trying to avoid.
A real argument for continuous scanning: a Mac in a household or office that shares files with Windows machines. A Windows executable attached to a forwarded email cannot run on macOS, but it can be passed on. Scanning helps the Windows machines, not yours.
A second real argument: a Mac used by someone who installs software freely and would not recognise a bundled installer. More aggressive blocking reduces the cleanup work.
If neither applies, on-demand scanning is sufficient.
What to do instead of buying a subscription
Higher value per minute spent.
- Keep macOS updated. XProtect definitions and security fixes arrive this way. System Settings → General → Software Update, with automatic updates on.
- Audit browser extensions occasionally. This is where the realistic Mac threat lives, and removing what you no longer use takes two minutes.
- Use a password manager and let it fill credentials, which gives you an automatic check that you are on the right domain every time you sign in.
- Turn on FileVault, under Privacy & Security. It encrypts the drive, which matters the moment a laptop is lost or stolen.
- Do not install cracked software. This is the main route by which macOS credential stealers reach people, and no scanner compensates for inviting it in.
- Never follow installation instructions given by a web page. Legitimate software does not need you to right-click, choose Open, and confirm past a warning.
If something already seems wrong, checking your Mac for malware walks through the four places to look before installing anything at all.
The claims to disregard
“Macs do not get viruses.” Outdated and unhelpful. The threat profile is different, not absent.
“Mac malware is growing by X percent.” Usually from a vendor’s own report, usually counting adware, and always attached to a product.
“Your Mac is infected” web pages. macOS does not report infection through a browser. Ever. Closing the tab is the complete fix, and if you have reached the stage of a telephone number on screen, how the fake virus warning scam works explains what happens next if you ring it.
Mac cleaner and optimiser applications. They find cache files and language packs and present them as problems. Several products in this category have behaved badly enough to be classified as unwanted software by other vendors.
Realistic expectations
A Mac kept updated, with software installed from the App Store or from developers’ own sites, and a browser whose extensions you can account for, is in good shape without any additional security software at all.
The honest residual risk is not technical. It is that one day a convincing page will tell you to install something and you will be in a hurry. No subscription prevents that. What helps is a free on-demand scanner for when you suspect you made that mistake, and the habit of treating any installation prompt you did not go looking for as a reason to stop.