Release notes for Safe Exam Browser version 3.7.1.1 for macOS:
Release notes for Safe Exam Browser version 3.7.1.1 for macOS:
SEB 3.7.1.1 is a maintenance update: it improves Full Disk Access detection on macOS 12, adds clearer error handling for failed configuration downloads and web page loads, and contains several stability and settings fixes.
New in SEB 3.7.1.1 (Build 15A08)
-
Improved Full Disk Access detection on macOS 12: SEB now distinguishes a Full Disk Access permission that is genuinely missing from one that has been granted but isn't effective — for example when the permissions of the macOS system permission (TCC) database folder have been changed from their default, or when the grant doesn't apply to the installed copy of SEB. Instead of repeatedly showing the "Grant Full Disk Access" prompt in a loop after the permission has already been enabled, SEB now reports the actual database-access error and offers guidance once granting the permission doesn't resolve it. Detection of apps with Accessibility permissions is also kept complete: if the system permission database cannot be read, SEB no longer treats the result as "no apps found".
The error reported by SEB indicates the cause: an "Operation not permitted" (errno 1) error means Full Disk Access simply isn't in effect (not granted, or the grant doesn't apply to this copy of SEB — reinstall it by dragging it into the Applications folder and grant it again). A "Permission denied" (errno 13) error instead means the file system blocked access because the permissions of the macOS privacy database folder have been changed from their macOS default.
If you get the "Permission denied" (errno 13) error, the default permissions of that folder are
drwxr-xr-x(mode 755), ownerroot, groupwheel. You can check the current permissions in the Terminal with:ls -lde "/Library/Application Support/com.apple.TCC"and restore the default permissions with:
sudo chown root:wheel "/Library/Application Support/com.apple.TCC" sudo chmod 755 "/Library/Application Support/com.apple.TCC"Note: this folder is normally protected by macOS System Integrity Protection (SIP), so these commands may report "Operation not permitted" even with sudo. In that case the permissions were likely altered while SIP was disabled or carried over by a migration or backup restore, and restoring them may require booting into macOS Recovery.
-
Fixed a silent white (blank) screen when a web page fails to load. WebKit does not report an error for HTTP error status codes (it simply renders the, often empty, response body) and a crashing web content process was reloaded silently. SEB now shows a load error alert (Retry/Cancel) for server error (5xx) and empty-bodied client error (4xx) responses instead of a blank page, and stops reloading after a web content process repeatedly terminates instead of looping on a white screen.
-
Fixed a misleading "settings are corrupted" message (and a possible crash) when downloading a configuration that completed but returned an HTTP error status or an empty body. SEB now shows a clear "Downloading Settings Failed" error in this case instead of trying to parse invalid data.
-
Improved robustness against crashes when reading corrupted or missing configuration/user data: deserializing invalid or empty data no longer aborts SEB, and such errors are handled gracefully.
-
Fixed a duplicate exam session being started after force quitting prohibited processes, which could incorrectly show the red "Re-Opening Locked Exam" screen.
-
Removed the outdated "Enable Plug-Ins" setting from Settings / Browser.
-
Further improved the Settings window (order and labels of settings) and added the "Allow printing (Win)" setting.
-
Remove the outdated setting browserWindowTitleSuffix when Saving As.
-
Security improvements.
-
Updated localizations.
Release notes for Safe Exam Browser version 3.7.1 for macOS:
SEB 3.7.1 adds the option to require specific SEB client versions in a configuration, allows fetching server certificates by URL in settings, and contains a security fix for certificate validation as well as several permission-handling and stability fixes.
New in SEB 3.7.1 (Build 159F8)
-
Added "Allowed SEB Versions": exam administrators can now require that a configuration may only be used (and an exam only attempted) with one or more specific SEB client version(s). If the SEB version running on the device doesn't match the requirement, SEB displays an alert stating which version(s) are required and offers to open the SEB download page ("Download SEB") or to quit; in both cases SEB is quit, so it can't be used for the exam with a disallowed version. The requirements are configured in Settings / Security (see the new setting sebAllowedVersions below).
As this feature will only make sense when there will only be SEB macOS clients circulating which support the version check and because that is more secure, you should preferably use server-side SEB client version restrictions. -
Added fetching server certificates by URL in Settings / Network / Certificates: certificates to embed can now be retrieved directly from a URL. This facilitates setting up certificate pinning to prevent MITM attacks.
-
Fixed improper certificate validation (CWE-295): removed the "authorized hosts" substring fallback in the server-trust evaluation, which could accept a certificate for a host whose name merely contained an authorized host name as a substring. Server trust is now matched correctly.
-
Added compatibility for passwords containing accented characters (é, ü, ñ) across platforms.
-
Fixed a crash when opening the Advanced Certificates sheet in Settings / Network / Certificates.
-
Detecting apps with Accessibility permissions (setting detectAccessibilityApps) requires Full Disk Access to read the system permission (TCC) database. On macOS 11 the system does not grant apps read access to this database even when Full Disk Access is enabled, so this detection is now only performed on macOS 12 and newer. On macOS 11 SEB no longer shows a Full Disk Access prompt that could never be satisfied and starts normally (the accessibility app detection is simply unavailable there). Accordingly, the default minimum required macOS version has been raised to macOS 12.
-
Fixed Full Disk Access permission detection on macOS 12, so SEB reliably recognizes when Full Disk Access has been granted. System permission prompts are now requested while the AAC Assessment Mode is off, and Full Disk Access is checked before requesting download/log folder access, so the prompts are shown reliably and aren't hidden behind the locked-down UI. Also the authorization dialog is no longer displayed when starting SEB with pressed option key (which displays Settings instead of starting a session).
-
Fixed several permission and information dialogs (Location Services and the "minimum macOS version required" alert) not being displayed — or SEB freezing or continuing without waiting for the user — when running under the AAC Assessment Mode on macOS 11. These alerts are now shown reliably and correctly block the session start.
-
Fixed the Full Disk Access and Location Services permission dialogs being inaccessible when reconfiguring from one Classic kiosk mode session to another: the dialogs were shown while the previous session's kiosk mode still covered the screen, so System Settings stayed hidden behind SEB and SEB took input focus back when the user tried to interact with it, making it impossible to grant the permission. While such a permission dialog is displayed, SEB now temporarily downgrades the Classic kiosk mode to allow switching to System Settings, brings the relevant System Settings pane to the foreground, and restores the kiosk mode once the permission has been granted or the dialog is dismissed.
-
Fixed Location Services not being requested when reconfiguring into a Classic kiosk mode session, so the Wi-Fi control showed that access wasn't granted without ever prompting for it. SEB now requests Location Services (when needed to display Wi-Fi network names) on such a reconfiguration, as it already did on the initial launch and when starting the AAC Assessment Mode.
-
Location Services access is now only requested when actually needed (to display Wi-Fi network names), when displaying the Wi-Fi control isn’t disabled and while SEB isn't locked down, so users aren't prompted unnecessarily. Also fixed the Location Services permission dialog not closing automatically on macOS 11 once access is granted in System Settings, and an unnecessary Location Services permission dialog briefly appearing on macOS 11 even when access was already granted.
-
Fixed SEB still taking input focus back from the genuine Apple-signed macOS SecurityAgent dialog (for example the keychain prompt shown when connecting to a Wi-Fi network) in situations where the system reported the change without a workspace notification. SEB now leaves this system dialog in the foreground in these cases as well.
-
Fixed holding the Option key while starting SEB not opening the Settings window when SEB was launched with deployed client settings (a SEBClientSettings.seb in the Library/Preferences/ folder). Holding the Option key at launch now opens Settings in this case too (if allowed in the client settings), instead of always starting a session.
-
Fixed the browser text search (find on page) altering text in saved open-text answers, for example when searching within an open-text question in OLAT.
-
The browser text search now also covers content inside iFrames.
-
The browser text search now draws the "N of M" match counter inside the search field.
-
Replaced the preset permitted process for the Cisco Secure Client with AnyConnect, which works when it is connected before starting SEB.
-
Reordered the settings in the Settings / Security pane to reflect their current status (general settings vs. macOS-only settings).
-
Added explanation about the Detect Accessibility Apps feature and Full Disk Access.
-
Security improvements.
-
Updated the hardcoded user agent string (with 3.7).
-
Updated localizations.
Optional features which need to be individually configured and are disabled by default
- Fixed the optional Screen Proctoring feature continuing without proctoring when the connection to the Screen Proctoring server failed. If SEB cannot establish or maintain the connection to the Screen Proctoring service (for example it cannot obtain an access token, or the token stays invalid after the configured number of attempts), SEB now shows an error alert and lets the user retry the connection or quit the session, instead of continuing the exam unmonitored.
New Settings
sebAllowedVersions — Array of strings, default empty (no restriction)
Settings window: Security → "Allowed SEB Versions"
Specifies one or more SEB client versions required in order to use a configuration. Enter one restriction per row. Each restriction has the format OS.Major.Minor.[Patch].[Build].[AE].[min], where the parts in square brackets are optional:
OS— the operating system:Win,MacoriOS.Major,Minor— the major and minor version (required).[Patch],[Build]— optionally the patch and build version.[AE]— optionally indicates the Alliance Edition.[min]— optionally marks the value as the minimum required version (this version or any newer one); without it, the restriction is an exact match on the components you specified.
Examples: Win.3.9.min allows all SEB for Windows versions from 3.9 upwards; Mac.3.7.1 requires exactly SEB for macOS 3.7.1.
A restriction only constrains the platform it names. As long as no restriction is configured for a given platform, all versions of that platform are allowed — so a configuration that only restricts, for example, SEB for Windows does not affect SEB for macOS or iOS. Only the version components you specify are compared, so Mac.3.7 allows any 3.7.x. A pre-release (beta) ranks just below its final release: for example 3.7.1b4 counts as below 3.7.1, so it satisfies Mac.3.7 but not Mac.3.7.1 or Mac.3.7.1.min. When the platform SEB is running on is restricted and the running version doesn't satisfy any of its restrictions, SEB shows an error message describing the requirement — phrased as a minimum ("… or higher") or as one or more specific versions, as configured — with a link to the SEB download page.
Release notes for Safe Exam Browser version 3.7 for macOS:
SEB 3.7 contains many important security improvements, a new Wi-Fi control especially helpful with AAC Assessment Mode and various fixes.
New in SEB 3.7 (Build 1591F)
-
Now the macOS Automatic Assessment Configuration (AAC) Assessment Mode is the default lockdown/kiosk mode. Choosing the kiosk mode is controlled with the new setting lockdownModePolicy described below.
-
Added a Wi-Fi control (widget) to the SEB Dock, which is automatically displayed in both the AAC Assessment Mode and the classic SEB lockdown mode, as the macOS menu bar is now always hidden. This lets users see the current Wi-Fi network and switch to another network during a session. When connecting to a network for the first time, SEB prompts for the network password (or a user name/password to read it from the Keychain) and stores it in a dedicated SEB Keychain item for subsequent connections to the same network. The Location Services permission alert (required to display Wi-Fi network names) closes automatically once access is granted in System Settings. The new setting hideWiFiControls (currently macOS only) allows to hide this control (see below for details).
-
Now detecting and terminating applications which have been granted macOS Accessibility permissions (which could be misused in exams) before and during an exam session. To be able to detect such apps, SEB requires Full Disk Access. If it is not granted, SEB asks the user to enable it in System Settings / Privacy & Security / Full Disk Access. SEB is not reading any other data than the macOS system list of applications with Accessibility permissions (also see our Privacy Statement). You should assess if some students require the use of legitimate accessibility tools and exempt those with a permitted processes entry with the
allowAccessibilityproperty enabled (see New Settings below). -
Now preventing Live Activities from an iPhone (for example a live sports score or timer, but also tools which could be used for cheating) from being displayed on the Mac during an exam session.
-
The macOS menu bar is now always hidden during a session and the previous “Show menu bar" option has been removed from Settings. On recent macOS versions the menu bar could no longer be reliably covered, so it is now always hidden.
-
The "Choose Application…" button in Settings / Applications / Permitted Processes now also reads the Team Identifier from the selected app's code signature and stores it with the permitted process. This makes matching additional applications more robust and secure when using the AAC Assessment Mode.
-
Added an "Add Preset Process…" button in Settings / Applications / Permitted Processes, with which the exam administrator can add processes hardcoded in SEB (similar to the preset default prohibited processes) or defined in the used SEB client settings. This also improves the setup for using the AAC Assessment Mode together with the Cisco Secure Client and similar VPN clients.
-
Implemented macOS 26 clipboard (pasteboard) history blocking also for the Classic (non-AAC) kiosk/lockdown mode (previously this was only handled when using the AAC Assessment Mode).
-
Allow to open Settings when starting SEB for the first time / with default client settings now works correctly. This solves access to settings if you want to set up SEB manually (as the setting "Allow to open Settings window on client" is by default disabled/false since SEB 3.6).
-
Improved support for multi-display setups: Fixed sizing and placement of the main browser window, the covering (background) windows and the lock screen (including when using the AAC Assessment Mode), and modal alerts are now centered on SEB's screen.
-
Fixed: In the AAC Multi-App Assessment Mode, additional (permitted) applications could be hidden behind the SEB browser window. SEB no longer forces its windows to the front while the AAC Assessment Mode is active, so permitted apps stay usable in the foreground.
-
Fixed: SEB took back focus from the genuine Apple-signed macOS SecurityAgent dialog (for example the keychain access prompt shown when connecting to a Wi-Fi network), which could prevent users from entering the requested credentials. SEB now leaves this system dialog in the foreground.
-
Fixed: When reconfiguring from one AAC Assessment Mode session to another AAC session, the per-application AAC configuration (for example the "allow network access" property of a permitted application) was not updated. SEB now restarts the AAC session so the changed settings take effect.
-
Fixed: Clicking a link or button that opens a new browser window in some web applications (for example certain popups in Moodle) could incorrectly bring up the "Quit SEB" dialog. This happened when the web page opened a window with an empty URL (for example window.open("") or window.open("", "_blank") followed by setting its location afterwards): the resulting navigation had an empty URL, which SEB's quit-link comparison didn't guard against and could mistake for a matching quit link. SEB now correctly ignores such empty-URL navigations instead of showing the quit dialog.
-
Fixed: Quit/admin passwords containing accented characters (like é, ü, ñ) were not recognized on macOS and iOS, while they worked on Windows — for example a quit password set in the Moodle quiz backend or in SEB for Windows could not be entered on a Mac or iPad, leaving users unable to exit SEB. The cause was a Unicode normalization mismatch: the same accented character can be encoded either precomposed (NFC, as produced by Windows and by web/PHP backends like Moodle) or decomposed (NFD, as often produced by text input on Apple platforms), which yields different bytes and therefore a different password hash. SEB now normalizes passwords to NFC before hashing, so hashes match across platforms, and additionally still accepts the previous (NFD) form for backward compatibility. This applies everywhere a password is entered to be checked: the quit/unlock password (including on the lock screen), the administrator password, the SEB Server fallback password, and the password used to decrypt encrypted configuration files.
-
Fixed: The document picker failed to open correctly when uploading a file attachment while using the Automatic AAC Assessment Mode. When migrating older settings in which AAC wasn't explicitly enabled, SEB now sets allowOpenAndSavePanel to true, as otherwise the document picker wouldn't be displayed in the Automatic AAC mode. SEB now also shows an error message if the document picker should be used but allowOpenAndSavePanel is false, and a warning in Settings / Down/Uploads when an upload policy other than "only allow to upload the same file downloaded before" is selected while allowOpenAndSavePanel is false and the Classic lockdown mode isn't used.
-
Fixed: SEB failed to recognize when a web application attempts to close the main browser window (the window containing the exam page). Closing that window is forbidden — a web application may only close windows it opened itself — and SEB then shows the quit dialog. Now SEB again correctly prevents that the main browser window is closed by a web app.
-
Fixed: The Config Key computed by SEB could differ between Windows and macOS/iOS for configurations containing floating-point setting values (for example zoom levels, battery charge thresholds or the screen proctoring image downscale factor), because the two platforms serialized these numbers differently. This could cause an exam system or SEB Server to reject an otherwise valid SEB client. SEB now formats floating-point values to more closely match SEB for Windows (interim improvement, see SafeExamBrowser/seb-win-refactoring#1495).
-
Fixed: The battery charge indicator in the SEB Dock sometimes displayed an incorrect charge level (different than the system indicator).
-
Fixed: When reconfiguring from SEB settings which have AAC active (for example when using default SEB Server connection settings), some system alerts were hidden. This mostly applied to the macOS Screen Recording and Accessibility permissions dialogues. SEB was then stuck and the Mac had to be force-restarted.
-
Fixed: User Agent string with trailing space causes web app error. As a workaround, if you cannot update to 3.7 yet, add some short user agent suffix, which is always appended at the end of the user agent string, which SEB is sending.
-
Fixed: SEBClientConfig.seb in Preferences folder leads to red screen "Re-Opening Locked Exam!".
-
Fixed: Can open spellcheck window from Dictation popup in AAC.
-
Fixed: Some websites using the SEB Javascript API crashed on older macOS versions.
-
Fixed: Modal alerts were displayed hidden behind SEB windows / the black background covering the screen after a transition from the AAC Assessment Mode to the Classic kiosk mode.
-
Fixed a crash during shutdown (caused by modifying the list of terminated processes while it was being enumerated).
-
Remove outdated settings when Saving As in the Settings window.
-
Added many additional preset prohibited processes, including remote access/control tools (for example RustDesk, Handy and UltraViewer) and further apps which request Accessibility permissions, as well as prohibited processes which were missing compared to SEB for Windows.
-
Optimized the code signature validation of running system processes. The check is now macOS version independent (also works on macOS 27).
-
Renamed the term "file selector" to the term Apple uses on macOS: "file dialog".
-
Improved logging (reduced repetitions and improved meaningfulness of log events). SEB now logs the list of running applications at session start (also when using the optional SEB Server) instead of at app start.
-
Changed the SEB source code license to the Mozilla Public License 2.0 (MPL 2.0) and updated the copyright year to 2026.
-
Updated localizations.
Optional features which need to be individually configured and are disabled by default
-
Screen Proctoring now also works together with the macOS AAC Assessment Mode, offering two different screen capture modes (active window and all windows (composite)). The compositing of the captured SEB windows into the screenshot runs off the main thread, so scrolling and other interactions stay smoother while screenshots are taken. If you still notice occasional hesitation while scrolling, you can increase the minimum screen shot interval (screenProctoringScreenshotMinInterval) in settings.
-
Fixed a crash that could occur when SEB Server or Screen Proctoring tried to create a network request on a connection that had just been closed (for example during the Full Disk Access permission flow or when ending the AAC Assessment Mode). The underlying "session has been invalidated" error is now handled gracefully instead of terminating SEB.
-
Further attempts to fix random crashes when using screen proctoring.
New Settings
lockdownModePolicy — Integer, default 0 (lockdownModePolicyAutomatic)
Settings window: Security
Controls which kiosk/lockdown mode SEB uses on macOS.
0lockdownModePolicyAutomatic— SEB automatically selects the lockdown mode based on the running macOS version and current settings. Automatic Assessment Configuration (AAC) is used when the macOS version supports it (≥ 10.15.4 except 10.15.5, ≥ 11 with DNS pre-pinning, ≥ 12.0 with DNS pre-pinning, ≥ 12.1 unconditionally) AND none of the following are enabled: screen capture, window capture, screen sharing, browser screen capture, or screen proctoring. Falls back to Classic kiosk mode otherwise.1lockdownModePolicyEnforceClassic— Always uses Classic kiosk mode (elevated window levels, no AAC), regardless of macOS version or other settings. Dictionary lookup is only available in this mode. The Settings window's Applications pane showsallowSwitchToApplicationsinstead ofallowOpenAndSavePanel.2lockdownModePolicyEnforceAAC— Always enforces Automatic Assessment Configuration (AAC). If the running macOS version does not support AAC, SEB logs an error and AAC is disabled at runtime. The Settings window's Applications pane showsallowOpenAndSavePanelandallowShareSheetinstead ofallowSwitchToApplications.
Migration: Configuration files that lack this key but have enableMacOSAAC=YES are automatically migrated to lockdownModePolicyEnforceAAC when their minimum macOS version requirement implies AAC support. If they don't have an according minimum macOS version requirement set, then they will get lockdownModePolicyAutomatic and therefore also use AAC on systems which meet the minimum supported macOS version (and don't have any of the screen/window capturing settings enabled, see above).
screenProctoringAACCapturePolicy — Integer, default 2 (screenProctoringAACCapturePolicyAllWindows)
Settings window: Security → "Screen proctoring capture under AAC"
Controls how the optional Screen Proctoring feature captures the screen while the AAC Assessment Mode is active. Under AAC the system screen-capture API returns black output, so SEB renders its own windows via a view-based capture instead; this setting selects what is captured.
0screenProctoringAACCapturePolicyNone— No view-based capture under AAC. In the automatic lockdown mode this also prevents AAC from being selected while screen proctoring is enabled (SEB falls back to Classic kiosk mode, where system capture works). If AAC is force-enabled anyway, capture falls back to the active window.1screenProctoringAACCapturePolicyActiveWindow— Captures only the active browser window (including its window chrome).2screenProctoringAACCapturePolicyAllWindows— Captures all SEB windows (browser windows, Dock, alerts) composited onto a full virtual-screen image. Content not in the view's backing store (e.g. hardware-accelerated or protected video) may appear black.
detectAccessibilityApps — Boolean, default true
Settings window: Security → "Detect apps with Accessibility Permissions"
When enabled, SEB detects apps that have been granted macOS Accessibility permissions (which could be misused to remotely control the Mac or automate other apps) and, unless explicitly permitted (see allowAccessibility), adds them to the prohibited applications list and terminates them before and during the session. Requires Full Disk Access; if it is missing, SEB prompts to enable it in System Settings / Privacy & Security / Full Disk Access.
allowAccessibility— Boolean, defaultfalse— property of apermittedProcessesentry
Settings window: Applications → Permitted (per selected app) → "Allow Accessibility"
Exempts one permitted application fromdetectAccessibilityApps, so it may keep its Accessibility permissions without being terminated (and is not terminated at session start even if already running).
hideWiFiControls — Boolean, default false (macOS only)
Settings window: User Interface → Dock
SEB automatically shows a Wi-Fi control (widget) in the SEB Dock when using the AAC Assessment Mode (the macOS menu bar is always hidden during a session), so users can view the current Wi-Fi network and switch networks without access to the menu bar. Set this to true to hide that Wi-Fi control even in those situations.