> Source: [sk184676](https://support.checkpoint.com/results/sk/sk184676)

# sk184676 - macOS Tahoe 26.3 (and later) Upgrade Causes Boot Failure and Recovery Loop - RESOLVED

| Property | Value |
|----------|-------|
| Solution ID | sk184676 |
| Date Created | 2026-02-12 |
| Last Modified | 2026-05-14 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |
| OS | macOS |

## Symptoms

- * macOS fails to boot after upgrading to Tahoe 26.3
* Device repeatedly enters Recovery Mode.
* System prompts for macOS reinstallation.

## Cause

This behavior occurs due to a compatibility change introduced in macOS Tahoe 26.3.

## Solution

Upgrading a Mac to macOS Tahoe 26.3 may cause the system to fail during startup. Affected devices may repeatedly enter Recovery Mode, fail to complete the boot sequence, or prompt for macOS reinstallation.

**Table of Contents:**

* Recommendation
* Recovery and Repair Procedures
  * Scenario 1: Devices Running E89.20 (Fully Repairable)
  * Scenario 2 - Devices Running E89.10 or Earlier (Bootable but Blades Disabled)
* Summary

Click Here to Show the Entire Article

Recommendation {#TARGET_ID_1}
-----------------------------

E89.21 client with the fix has been released, see [sk184630](https://support.checkpoint.com/results/sk/sk184630).  
This is the recommended version to upgrade to before upgrading to Mac OS Tahoe 26.3  

Recovery and Repair Procedures {#TARGET_ID_2}
---------------------------------------------

Choose the procedure that matches the installed Harmony Endpoint version.

### Scenario 1: Devices Running E89.20 (Fully Repairable) {#TARGET_ID_3}

Use this procedure only if:

1. macOS Tahoe 26.3 is installed.
2. The Mac is constantly rebooting or entering Recovery Mode.
3. Harmony Endpoint client version E89.20 is installed.
4. You are performing this repair for the first time.

This procedure restores the Mac with all blades running.  
Click to Show / Hide this procedure  
>
> #### Step 1 - Enter Recovery Mode and Mount the System Volume
>
> 1. Boot to Recovery Mode  
>    * For **Apple silicon** , press and hold the Power button until the boot options appear, then select **Options**.
> 2. Mount the main data volume.
>    * If FileVault is enabled, use **Disk Utility** to unlock and mount the system volume using the user's password.  
>      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1770905292592/undefined (2)202602120920593.png)
>    * After mounting, the main data volume will appear as: `"/Volumes/Macintosh HD - Data"`  
>      Where the volume name could be different.
>
> #### Step 2 - Replace the Faulty File
>
> 1. On another computer, prepare a USB thumb drive containing the fixed file: [efr-mon-epsec.dylib](https://support.checkpoint.com/results/download/141736)
> 2. Insert the USB drive into the affected Mac.
> 3. Open **Terminal** in Recovery Mode.
> 4. change directory:
>    * `cd "/Volumes/Macintosh HD - Data/Library/Application Support/Checkpoint/Endpoint Security"`
> 5. Remove the existing file:
>    * `rm efr-mon-epsec.dylib`
> 6. Copy the fixed file from the USB drive:
>    * `cp /Volumes/usb_stick/efr-mon-epsec.dylib .`
> 7. Reboot the Mac.
> After reboot, the kernel panic should be resolved and all blades should run normally.
> **Note** - Do not deploy any software updates or push any client package to affected machines at this stage.  
> Any deployment will restore the faulty file, causing the kernel panic to reoccur, requiring the repair to be repeated.  
> If you have completed these steps already,

### Scenario 2 - Devices Running E89.10 or Earlier (Bootable but Blades Disabled) {#TARGET_ID_4}

Use this procedure if the Mac is running Endpoint client versions E88.x or E89.10, or any version below E89.20.  
This process restores Mac bootability, but some Threat Prevention blades will remain disabled until the E89.21 client is installed.  
Click to Show / Hide this procedure  
>
> #### Step 1 - Enter Recovery Mode and Mount the System Volume
>
> 1. Boot to Recovery Mode  
>    * For **Apple silicon** , press and hold the Power button until the boot options appear, then select **Options**.
> 2. Mount the main data volume.
>    * If FileVault is enabled, use **Disk Utility** to unlock and mount the system volume using the user's password.  
>      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1770905292592/undefined (2)202602120920593.png)
>    * After mounting, the main data volume will appear as: `"/Volumes/Macintosh HD - Data"`  
>      Where the volume name could be different.
>
> #### Step 2 - Disable LaunchDaemons Causing the Boot Failure
>
> 1. change directory:
>    * `cd "/Volumes/Macintosh HD - Data/Library/LaunchDaemons"`
> 2. remove files:
>    * `rm com.cp.efr.agent.plist`
>    * `rm com.cp.te.agent.plist`
>    * `rm com.cp.ar.agent.plist`
>    * `rm com.checkpoint.efr-mon-epsec.plist`
>    * `rm com.checkpoint.threat-hunting.plist`
> 3. Reboot the Mac from the menu or use the reboot command from the terminal.
>
> <br />
>
> The Mac should now boot and allow login.  
>
> #### Blades Disabled in This State
>
> The following blades will not run until the updated client is installed:  
>
> * Threat Emulation
> * Forensics and Anti?Ransomware
>
> To fully restore protection, upgrade to the E89.21 mac client version that addresses the compatibility changes introduced in macOS Tahoe 26.3.   
> <https://support.checkpoint.com/results/sk/sk184630>  
> **This is available for Cloud Customers and for On Premise customers, please contact support.**

Summary {#TARGET_ID_5}
----------------------

|------------------------------------------------------------------------------|------------------------------------------------------------------|----------------------------------------|------------------------------------------------------------------------------------------------------------------|
| **Scenario**                                                                 | **Endpoint Client Version**                                      | **Result**                             | **Next Action**                                                                                                  |
| Scenario 1: Devices Running E89.20 (Fully Repairable)                        | E89.20                                                           | Fully repairable - all blades restored | Replace the file via USB, reboot the system, and upgrade to the new Harmony Endpoint client once it is released. |
| Scenario 2: Devices Running E89.10 or Earlier (Bootable but Blades Disabled) | E89.10 and lower                                                 | Bootable, but TP blades disabled       | Remove LaunchDaemons, reboot, and upgrade to the new Harmony Endpoint client update when it is released.         |
| Preventive                                                                   | Any Endpoint client version before upgrading to macOS Tahoe 26.3 | Avoid issue entirely                   | Install E89.21 (or later)                                                                                        |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
