Sample Header Ad - 728x90

Why am I able to open Wireshark and capture packets in macOS without root privileges?

12 votes
1 answer
5654 views
As far as I know, capturing packets using Wireshark requires root/administrator privileges. In Windows, it prompts for UAC elevation and runs with administrative privileges. The same thing in Ubuntu; it prompts for a password to authorize access before showing me the interfaces. However, in macOS, there is no authorization required. I don't have to enter a password. Instead, Wireshark is directly showing me the interfaces and I am able to capture packets. How is Wireshark able to do this on macOS? What is special about macOS that allows interfaces and packets to be monitored *without* administrative access?
Asked by scipsycho (359 rep)
Feb 27, 2019, 12:04 PM
Last activity: Apr 2, 2019, 07:09 AM