Skip to content

MacPublished 6 min read

The Mac login keychain lock-in is pinned to macOS Tahoe 26.4 (September 13, 2026)

Illustration for the article “The Mac login keychain lock-in is pinned to macOS Tahoe 26.4 (September 13, 2026)”
Listen to this article · 8:05 · AI-generated narration
0:00 / 8:05
Chapters

What is new on September 13

AppleInsider published at 16:15:52Z on September 13, 2026 and put a version number on the change. Verbatim: "Testing confirmed that the ability to copy the file worked for macOS 26.3, including via a virtual machine. However, copying the login Keychain from a virtual machine running macOS 26.4 didn't work, due to not being able to be read on other Macs." Until this, the reports named Tahoe generally.

Two other details were not in the earlier coverage. The article describes the login keychain as "a SQLite database file stored in the user's home folder", and it states that "Other non-login Keychain files are unaffected and can be unlocked on other Macs fine." The second is the more useful of the two, because it narrows the failure to the login keychain rather than to keychains as a concept.

It also credits the origin of the finding, Der Flounder's post of September 8, 2026, and records an update from the author of the analysis: "In an addendum on September 11, Johnson writes that this was a ticking time bomb that Apple included in a minor macOS update."

macOS versionCopying a login keychain file to another Mac
macOS Tahoe 26.3Worked, confirmed in AppleInsider's testing including from a virtual machine
macOS Tahoe 26.4Stopped working: the copied file cannot be read on other Macs
macOS Tahoe 26.6.2Still fails
macOS 27 Golden Gate release candidateMigration Assistant carried the contents in; a file copy is still not a route

TL;DR

The Mac login keychain copy failure now has a version attached to it: copying worked from macOS Tahoe 26.3 and stopped working from 26.4, according to AppleInsider on September 13, 2026. That is the new fact three days after the September 10 post, along with the first mainstream coverage, a stated cost for administrators running bulk migrations, and independent testing showing that Migration Assistant does carry login keychain contents across. Apple has still acknowledged nothing and there is still no fix.

  • AppleInsider's testing: copying worked for macOS 26.3, including from a virtual machine, and did not work from 26.4.
  • The login keychain is "a SQLite database file stored in the user's home folder", and the Secure Enclave holds the key that protects it.
  • Non-login keychain files are unaffected and still unlock on other Macs.
  • Migration Assistant does copy login keychain contents successfully, including into a macOS 27 Golden Gate release candidate.
  • Unacknowledged by Apple and unfixed as of September 13, 2026, five days after the first report.

Migration Assistant is the path that works

The Eclectic Light Company reproduced the failure independently on September 11, 2026 and described it without hedging: "you enter the correct password but it's refused, and there's no way of obtaining access. This makes copying keychains between Macs worthless." Its advice is equally direct: "If you intend migrating manually between Macs, don't waste time trying to copy across the login keychain".

The same testing found what does work, and this is the part the earlier reports did not have. Eclectic Light "demonstrated that Migration Assistant does copy the contents of the login keychain successfully to the destination Mac", including a migration whose destination was a macOS 27 Golden Gate release candidate, and its conclusion is that "The most reliable way to migrate login keychain contents is using Migration Assistant."

It also names the hinge: "unlocking a keychain on those now involves a secret kept within their Secure Enclave." Der Flounder's log line from September 8 is still the signature to look for, "SecKeychainLogin failed: -2147413984, password was supplied", and it now has a version range around it.

What it costs an administrator

AppleInsider states the enterprise consequence plainly: "it will be a problem for administrators performing bulk migrations in a corporate environment". The remedy is Migration Assistant, and Migration Assistant runs one machine at a time with a person in front of it, which is not how a fleet gets moved.

The second cost is recovery rather than migration. If a Mac is dead and the file is all you have, there is no file-level or offline route to the contents. Der Flounder published no manual workaround on September 8 and nobody has published one since, so the honest advice for that case is to reset the credentials rather than to keep trying.

The one piece of good news is in AppleInsider's own account: non-login keychain files still unlock on other Macs. A custom keychain is therefore the part of this system that still travels by file copy, which makes it worth using deliberately for credentials that have to outlive the hardware.

Still unacknowledged

Five days after the first report, Apple has said nothing. The line from Lapcat Software's analysis of September 10, 2026 still stands: "To my knowledge, Apple did not even publicize the change in Tahoe." The macOS 26.4 release notes do not mention the change, no support document describes it, and no fix has shipped as of September 13, 2026.

Who is exposed: anyone on macOS Tahoe 26.4 or later on a Mac with a Secure Enclave. The exposure stays invisible until a migration or a recovery, which is what makes this one worth acting on before you need to. Johnson's summary from the first report is the sentence to keep: "You do not and cannot have a reliable backup of your login keychain."

What is still unknown is whether Apple intends this. The behavior is consistent with the Secure Enclave design Der Flounder quoted from Apple's documentation, and nobody has published a statement either way, so I am not going to call it a bug or a decision.

What to do today

1. Migrate with Migration Assistant, not by copying login.keychain-db. Eclectic Light's tests on September 11 are the reason, and they include a Golden Gate release candidate as the destination. 2. Before you wipe or retire a Mac, confirm on the replacement that the credentials you need are actually there. While the old Mac still boots, it is the only place that keychain opens.

3. If you manage more than a handful of Macs, rewrite any migration runbook that copies the login keychain file. Plan for hands-on Migration Assistant runs, or move the credentials that matter out of the login keychain, because there is no bulk equivalent published.

4. Keep anything you must be able to recover in a custom keychain or another store, since non-login keychain files still unlock elsewhere. 5. If a Mac is already gone and you hold only the copied file, reset those credentials instead of trying to open it. Nothing published opens that file on other hardware, and the version bisect on September 13 makes it clear this has been true since 26.4.

Frequently asked questions

Is macOS 26.3 a safe place to stay?

AppleInsider's testing says copying worked on 26.3, but staying on an older macOS to keep a file-copy path is a poor trade against missing security updates. Use Migration Assistant instead and stay current.

What changed between the September 10 report and now?

Three things: the version was bisected to macOS Tahoe 26.4, mainstream coverage named the cost for administrators running bulk migrations, and independent testing confirmed Migration Assistant carries the keychain contents across. The bug itself is unchanged and unfixed.

All articles