Wireshark-ChmodBPF
Wireshark Foundation · Install macOS BPF-device permissions for unprivileged packet-capture tools.
About
Wireshark-ChmodBPF installs the macOS packet-capture permission helper distributed inside Wireshark's disk image. It is intended for users of packet-capture tools who need access to BPF devices without running the capture application as root. This package installs the ChmodBPF launch daemon, not the Wireshark graphical analyzer. Install your capture program separately if you need one.
Installation, distribution size and dependencies
The catalog 4.6.9 download is the official Wireshark 4.6.9 DMG, exactly 147,277,050 bytes; that is the entire containing distribution, not the much smaller extracted helper or installed footprint. Open Install ChmodBPF.pkg inside the DMG, or use brew install --cask wireshark-chmodbpf. Administrator authorization is required. The cask installs only that package and documents a reboot before use. It conflicts with the separately packaged Wireshark app cask; avoid installing redundant permission helpers.
The helper relies on macOS BPF device nodes, launchd and local group management. It is a system script/service rather than a standalone GUI. Exact minimum macOS, CPU coverage and RAM requirements for the catalog installer were not independently established. A packet analyzer's performance requirements depend on capture rate and analysis workload; they are not requirements invented for this permission script.
Security and permissions
The installer creates or uses the access_bpf group, adds the installing user, and grants group access to /dev/bpf* at boot. The official script explains that group members can capture or send raw packets. This is consequential system-wide network access: grant membership only to trusted users and software, and review group membership and the launch daemon after installation. Captures can contain personal data, credentials or third-party traffic; obtain authorization and protect capture files. It does not grant permission to monitor networks you do not administer.
Accounts, licensing and removal
The local helper does not need a Wireshark account, subscription or cloud service to operate. Network access is needed to download updates; actual capture interfaces and remote capture have separate requirements. Wireshark's official source is GPLv2-or-later and free/open-source; third-party components have their own notices. Remove the helper through its provided Uninstall ChmodBPF package or the package manager, then verify the remaining group and service configuration rather than deleting unrelated system files.
Version and media evidence
The catalog bases 4.6.9, 4.6.8 and 4.6.7 identify the containing Wireshark distributions, not independent ChmodBPF version numbers. Each official tagged macOS build configuration builds the ChmodBPF component as version 1.2 and includes its Install and Uninstall packages in the parent DMG. Selected packaging notes compare the helper source tree with the preceding Wireshark tag: the entire ChmodBPF source subtree is identical across 4.6.6 through 4.6.9. This establishes unchanged helper source for these parent-release transitions, not identical compiled packages, signatures or whole disk images, and does not attribute analyzer fixes to the helper. The icon is the official Wireshark installation-family mark used for this bundled component, not an independent ChmodBPF brand. A verified helper installation or permission-workflow image remains unavailable; the analyzer's packet-list window is not presented as a helper GUI.
Sources: Official Mac installation guide, Official ChmodBPF script, Installer postinstall, Official source/license.
Packaging sources: Tagged component build configuration, Tagged DMG contents, Official installation-family icon.
New What’s new in 4.6.9 Oct 7 · OpenNavo editorial
- PackagingParent Wireshark distribution advances from 4.6.8 to 4.6.9.
Caveats
This cask will install only the ChmodBPF package from the current Wireshark stable install package. An access_bpf group will be created and its members allowed access to BPF devices at boot to allow unprivileged packet captures. This cask is not required if installing the Wireshark cask. It is meant to support Wireshark installed from Homebrew or other cases where unprivileged access to macOS packet capture devices is desired without installing the binary distribution of Wireshark. The user account used to install this cask will be added to the access_bpf group automatically. You must reboot for the installation of wireshark-chmodbpf to take effect.