Skip to main content
Illustration for the macos kexts vs driverkit guide

macOS Kexts vs DriverKit

The architectural difference between kernel extensions and DriverKit system extensions, including security, deployment, and hardware-support limits.

By Sarah Jenkins Updated 2024-03-01Reviewer: Sarah Jenkins (2024-05-11)

Apple has moved many third-party device drivers out of the macOS kernel. DriverKit provides user-space frameworks for supported device classes while preserving controlled access to hardware.

Topic 1

Kernel extensions

A kext executes with kernel privilege and can affect the stability and security of the entire system. Modern macOS applies signing, notarization, user approval, and reduced-security requirements to legacy third-party kext deployment on Apple silicon.

Topic 2

DriverKit model

A DriverKit driver runs in a separate user-space process managed by the system. Entitlements define its hardware and family access. A crash can be isolated from the kernel, but only device classes represented by DriverKit frameworks can use this model.

Topic 3

Compatibility consequences

Older peripherals whose vendors supplied only kexts may lack support on newer macOS or Apple silicon. Rosetta translates applications, not kernel extensions, and cannot convert an Intel-only kext into an Apple-silicon driver.