Which: They do actually have some container-like sandboxing tech around applications (“iTerm wants to access your downloads folder”).
https://bdash.net.nz/posts/tcc-and-the-platform-sandbox-poli... and https://bdash.net.nz/posts/sandboxing-on-macos/ are good introductory articles.
Which: They do actually have some container-like sandboxing tech around applications (“iTerm wants to access your downloads folder”).