What Is /Library/PrivilegedHelperTools on Mac?

System (root-owned)Updated

Definition
Full path
  • /Library/PrivilegedHelperTools
Scope
System (root-owned)Shared by every account on the Mac and owned by macOS (root).
Freshist & this folder
Freshist checks this folder when uninstalling an app. When you uninstall an app, Freshist only considers items directly inside this folder whose name matches the app's bundle ID. They're never pre-selected, and because the folder is owned by macOS (root), selected items are deleted permanently by Freshist's signed helper rather than moved to the Trash.

From Freshist's own cleaning rules — the same catalog the app uses.

Why apps install helpers

A regular Mac app runs with your user's permissions. Some jobs need more than that: managing network interfaces, installing software system-wide, controlling hardware, setting up virtual machines. Rather than running the whole app as root, macOS lets an app install a small, separately signed privileged helper that does only those tasks.

For years Apple's mechanism for this was SMJobBless. It copies the helper binary into /Library/PrivilegedHelperTools and writes a launchd plist with the same label into /Library/LaunchDaemons. The app then talks to the helper over XPC. Apple has since introduced SMAppService, which keeps the helper inside the app bundle. You'll still find many helpers here, though, because widely used apps continue to install them the older way.

The leftover problem

SMJobBless has no uninstall step. When you drag the app to the Trash:

PieceWhereAfter the app is deleted
App/ApplicationsGone
Helper binary/Library/PrivilegedHelperTools/<label>Still there
Launchd plist/Library/LaunchDaemons/<label>.plistStill there; can keep starting the helper as root

A helper that runs as root with no app to talk to has no purpose, and it no longer receives updates. Some developers ship an uninstaller or a "remove helper" option for this reason.

Inspecting it read-only

ls -la /Library/PrivilegedHelperTools
ls -la /Library/LaunchDaemons
codesign -dvv /Library/PrivilegedHelperTools/com.example.helper
sudo launchctl print system/com.example.helper

The file name of a helper is normally its launchd label, so the matching plist is easy to spot. codesign -dvv shows who signed the helper (the Authority and TeamIdentifier lines), which tells you the vendor even when the name is cryptic. launchctl print shows whether it's currently loaded and running.

Removing a leftover helper

  1. Look for the vendor's own removal option first, in the app's settings, its uninstaller or its support pages.
  2. If the app is already gone, unload the job, then remove both files:
sudo launchctl bootout system /Library/LaunchDaemons/com.example.helper.plist
sudo rm /Library/LaunchDaemons/com.example.helper.plist
sudo rm /Library/PrivilegedHelperTools/com.example.helper
  1. Restart the Mac.

Finder works too: drag both items to the Trash and enter an administrator password. Unload the job first, though, or the helper keeps running until you restart.

Keep helpers for apps you still use. Removing one doesn't break the app permanently, but it will ask for your password again to reinstall it, and features that depend on it stop until it does.

Freshist and helper names

As the facts box notes, Freshist only offers items here when their name matches the app's bundle ID, and deletes them permanently because the folder belongs to root. Helper labels often differ from the app's ID, such as com.example.vmnetd for an app identified as com.example.app, so check this folder and LaunchDaemons yourself after removing an app that once asked for your password. The full checklist is in how to uninstall apps completely, and /safety/ explains how Freshist handles folders owned by macOS.

Sources

Frequently asked questions

Why did an app ask for my password once and never again?

That's usually the moment it installed its privileged helper. From then on the helper does the root-level work, and the app talks to it without asking you again.

Do all apps that need admin rights put a helper here?

No. Apps built on Apple's newer SMAppService API keep their helper inside the app bundle and register it with macOS, so nothing is copied to this folder and deleting the app removes it.

Is the helper still running after I deleted the app?

Possibly. If its launchd plist is still loaded, launchd can keep starting it. Check with sudo launchctl print system/<label>, and restart after removing the files.

Keep reading