Skip to content

Glossary

client_type

The TCC.db column that says how the client is identified: 0 for a bundle ID such as com.apple.Terminal, 1 for an absolute path to a binary.

client_type tells you how to read the client column of TCC.db: 0 means a bundle identifier (for example com.apple.Terminal), 1 means an absolute path (for example /usr/local/bin/tool).

Legitimate apps are almost always recorded by bundle ID. Path-based clients are typically command-line tools, scripts or unpackaged binaries, and a path in a temporary, shared or hidden folder is worth a closer look. See investigating TCC permission abuse.