What post-install kexts are and why you might need them
A kext (kernel extension) is a piece of software that runs at the core level of macOS, letting hardware and software talk to each other. Most kexts come built into macOS or install automatically when you add new hardware. A post-install kext is one you install after macOS is already running — usually because you've added hardware that macOS doesn't recognize on its own, or because you're using a hackintosh (a non-Apple computer running macOS).
Installing kexts through Terminal means you're using command-line tools instead of a graphical installer. This method gives you more control and lets you see exactly what's happening during installation. It's also the standard way to install kexts on a hackintosh or when graphical installers don't work.
Before you start, understand that kexts run at a privileged level in your system. Installing the wrong kext, or installing a kext incorrectly, can make your Mac unstable or prevent it from starting. Always download kexts only from trusted sources — the developer's official website or established hackintosh communities like OpenCore Legacy Patcher or Dortania.
Key Takeaways
- Download kexts only from official developer websites or established hackintosh communities, never from random download sites.
- Most post-install kexts go into /Library/Extensions or /System/Library/Extensions, depending on whether your Mac uses Intel or Apple silicon.
- After copying a kext to its folder, you must rebuild the kernel cache using Terminal commands so macOS recognizes it.
- Disable System Integrity Protection (SIP) before installing kexts on Intel Macs, then re-enable it afterward for security.
- If a kext causes problems, you can remove it by deleting the file and rebuilding the cache again.
Disable System Integrity Protection on Intel Macs
On Intel-based Macs, System Integrity Protection (SIP) prevents you from modifying system files, including the folders where kexts live. You need to turn it off temporarily to install kexts, then turn it back on when you're done.
Restart your Mac and hold Command + R to enter Recovery Mode. Open Terminal from the Utilities menu. Type this command and press Enter:
csrutil disable
You'll see a message confirming that SIP is off. Restart your Mac normally. You can now install kexts. After you finish installing all your kexts and rebuild the kernel cache, come back to Recovery Mode and run csrutil enable to turn SIP back on.
Note: Apple silicon Macs (M1, M2, M3, and newer) handle kexts differently and have stricter security. Most third-party kexts don't work on Apple silicon at all. If you're on Apple silicon, check whether the kext you want to install actually supports your Mac before proceeding.
Download and locate your kext file
Find the kext you need from the official source. For example, if you need a driver for a USB controller, go to the manufacturer's website or the Dortania hackintosh guide and download the kext file directly. The file will have a name like USBInjectAll.kext or AppleALC.kext.
The downloaded file is usually a compressed archive (a .zip file). Double-click it to extract the actual .kext folder. You should now have a folder with a name ending in .kext — this is what you'll install.
Open Terminal and navigate to the folder where your kext is. If it's on your Desktop, type:
cd ~/Desktop
Then type ls and press Enter to list the files in that folder. You should see your .kext folder listed.
Copy the kext to the correct system folder
On Intel Macs running recent versions of macOS, kexts go into /Library/Extensions. On older Intel Macs or certain hackintosh setups, they go into /System/Library/Extensions. Check the kext's documentation or the guide you're following to know which folder is correct for your situation.
To copy the kext, use the cp command in Terminal. If your kext is called USBInjectAll.kext and it goes in /Library/Extensions, type:
sudo cp -r USBInjectAll.kext /Library/Extensions/
Press Enter. Terminal will ask for your password — type it in (you won't see the characters as you type, which is normal) and press Enter again. The kext is now copied to the system folder.
If you need to install multiple kexts, repeat this step for each one before moving to the next section. This saves time because you'll only rebuild the kernel cache once.
Rebuild the kernel cache so macOS recognizes the kext
After copying kexts to the system folder, macOS needs to rebuild its kernel cache — a file that tells the system which kexts are available. Without this step, your Mac won't load the new kext even though it's in the right folder.
In Terminal, type this command and press Enter:
sudo kextcache -i /
This command scans all system folders and rebuilds the cache. It may take a minute or two. You'll see output in Terminal showing the progress. When it finishes, you'll see a prompt ready for a new command.
On some Intel Macs, you may also need to run:
sudo touch /Library/Extensions
This updates the timestamp on the Extensions folder, which can help macOS recognize the change. Then rebuild the cache again with the kextcache command above.
Restart your Mac and verify the kext loaded
Restart your Mac normally. When it boots up, the new kext should load automatically. To check whether it worked, open Terminal and type:
kextstat | grep -i YourKextName
Replace YourKextName with part of your kext's actual name. For example, if you installed USBInjectAll.kext, type:
kextstat | grep -i USB
If the kext loaded successfully, you'll see a line of output with the kext's name and some numbers. If you see nothing, the kext didn't load — check that you copied it to the right folder and that the kernel cache was rebuilt correctly.
If the kext causes problems (your Mac won't start, crashes, or hardware doesn't work), restart into Recovery Mode, disable SIP again, delete the kext file from the system folder, rebuild the kernel cache, and restart. Then re-enable SIP.
Re-enable System Integrity Protection when finished
Once all your kexts are installed and working, turn System Integrity Protection back on for security. Restart your Mac and hold Command + R to enter Recovery Mode. Open Terminal and type:
csrutil enable
Press Enter. You'll see a confirmation message. Restart your Mac normally. SIP is now back on, and your kexts will continue to work — SIP only prevents new changes to system files, not the use of kexts that are already installed.
Frequently Asked Questions
What if I get a "permission denied" error when copying the kext?
You probably forgot the sudo command at the start, or SIP is still enabled on an Intel Mac. Make sure you type sudo before the cp command, and on Intel Macs, confirm that you disabled SIP in Recovery Mode before restarting.
Can I install kexts on an Apple silicon Mac?
Most third-party kexts don't work on Apple silicon Macs at all because Apple redesigned how the system loads kernel extensions. Check the kext's documentation first. If it doesn't explicitly say it supports Apple silicon, it won't work on your Mac.
How do I know if a kext is from a trusted source?
Download only from the official developer's website or from established hackintosh guides like Dortania or OpenCore Legacy Patcher. Avoid random download sites or forums where you can't verify who created the file. If you're unsure, ask in a hackintosh community before installing.
What happens if I install a kext that's incompatible with my macOS version?
Your Mac may fail to start, or the kext simply won't load. If your Mac won't start, restart into Recovery Mode, disable SIP, delete the kext, rebuild the cache, and restart. Always check the kext's documentation for which macOS versions it supports before installing.