Skip to main content
Mole
Features Tested apps Testimonials Pricing FAQ Blog
EnglishEN 简体中文中 繁體中文繁 日本語日 한국어한 FrançaisFR DeutschDE ItalianoIT EspañolES PortuguêsPT
Buy nowBuy Download

    Help, documentation, releases, and articles.

    Home/Apps tested with Mole

    Uninstall Wireshark on Mac

    Wireshark installs more than the app: a background ChmodBPF service quietly grants your account permission to capture packets without running Wireshark as root, and it stays on your Mac even after Wireshark.app is gone unless you remove it separately. This guide covers the official DMG from wireshark.org and the Homebrew cask wireshark-app; each removes ChmodBPF through its own mechanism, described below.

    Quit Wireshark and finish any capture in progress

    Stop any running capture and quit Wireshark from its menu. Wireshark itself has no separate login item or menu-bar helper; only ChmodBPF runs as a system service, independent of whether the app is open.

    Remove ChmodBPF, the packet-capture permission service

    ChmodBPF installs a LaunchDaemon (org.wireshark.ChmodBPF) and creates a macOS group called access_bpf that is allowed to read the packet-capture devices; every account added to it can capture without sudo. Moving Wireshark.app to the Trash does not touch either one.

    • Official DMG: open the Wireshark DMG again (mounting the one you installed from is enough) and run Uninstall ChmodBPF.pkg, which sits next to Wireshark.app in the disk image window. It stops the LaunchDaemon, removes the access_bpf group if nothing else depends on it, and deletes /Library/Application Support/Wireshark. The same DMG also carries Remove Wireshark from the system path.pkg, which drops the entries that put tshark and Wireshark's other command-line tools on your PATH. After both uninstallers finish, move Wireshark.app from Applications to the Trash.
    • Homebrew: brew uninstall --cask wireshark-app stops and unloads the ChmodBPF LaunchDaemon, runs the bundled path-removal installer, and removes files tracked by Wireshark package receipts before forgetting those receipts, with or without --zap. Mole does not add a separate privileged step of its own for this; it relies entirely on brew's own uninstall stanza.

    Mole itself never installs or removes ChmodBPF or the access_bpf group; that stays between you, the official uninstaller pkg, and Homebrew. Confirm it is actually gone with the commands below regardless of which channel you used.

    Where Wireshark keeps its data

    Location What it holds What to do
    /Library/Application Support/Wireshark ChmodBPF's installed script and supporting files System-level review row requiring admin; cleared by the official Uninstall ChmodBPF.pkg or by brew, not by moving the app alone
    ~/.config/wireshark Your capture filters, display filters, recent files, and profiles Unselected with Remove data and settings with apps off; check this row before removing saved configuration
    ~/Library/Caches/org.wireshark.Wireshark App cache Selected by default
    ~/Library/Cookies/org.wireshark.Wireshark.binarycookies Cookies Selected by default
    ~/Library/HTTPStorages/org.wireshark.Wireshark and ~/Library/HTTPStorages/org.wireshark.Wireshark.binarycookies HTTP storage Selected by default
    ~/Library/Preferences/org.wireshark.Wireshark.plist App preferences Selected by default
    ~/Library/Saved Application State/org.wireshark.Wireshark.savedState Saved window state Selected by default
    ~/Library/WebKit/org.wireshark.Wireshark Embedded web view data Selected by default

    Check the result

    Run these read-only commands in Terminal:

    pgrep -ilf wireshark
    launchctl print system/org.wireshark.ChmodBPF
    dscl . -read /Groups/access_bpf
    ls -d ~/.config/wireshark
    pkgutil --pkgs | grep -i wireshark
    

    No output from pgrep means no Wireshark process is running. launchctl print targets the system daemon: a service record means it is still registered; state = running means it is running. A service-not-found message means that daemon is no longer registered. Permission errors or another failed check do not establish removal. dscl prints the group's details if access_bpf still exists, or eDSRecordNotFound once it's been removed. The group can outlive the daemon if something else stops it without running the uninstaller. ls -d on ~/.config/wireshark prints the folder path if it exists, or "No such file or directory" once it's gone. A remaining org.wireshark.* line from pkgutil means an installer receipt is still registered, harmless on its own once the files it named are gone.

    If you installed it with Homebrew

    Mole skips --zap when its list reaches unchecked or shared data, or cannot be fully checked, and still cleans the leftovers you selected.

    When you run brew uninstall --cask --zap wireshark-app yourself, before the zap step even runs, the cask's own uninstall stanza stops and unloads the ChmodBPF LaunchDaemon, runs the path-removal installer, and deletes files tracked by Wireshark package receipts before forgetting the receipts, whatever you left checked in Mole. The zap list itself trashes /Library/Application Support/Wireshark, ~/.config/wireshark (your capture and display filters), the app cache, cookies, HTTP storage, preferences, saved window state, and the embedded WebKit data, all of it, regardless of Mole's checkboxes. Back up ~/.config/wireshark first if you want to keep your filters and profiles, or uninstall without zap:

    brew uninstall --cask wireshark-app
    

    Wireshark's ChmodBPF and path-helper installer sources · Homebrew Wireshark cask

    What Mole lists

    ~/.config/wireshark is listed but unselected while Remove data and settings with apps is off, the default. Enabling that option can preselect eligible app-owned configuration; untick this row to keep your filters and profiles. /Library/Application Support/Wireshark appears as an admin-gated system-level review row, also never selected by default. The other paths in the table above are ordinary bundle-identified app data and are selected by default like any other app's cache, cookies, and preferences. Mole does not manage the org.wireshark.ChmodBPF LaunchDaemon or the access_bpf group in any channel; removing them is left to the official Uninstall ChmodBPF.pkg or to Homebrew's own uninstall step.

    What this test covered

    Wireshark was installed from the Homebrew cask wireshark-app and uninstalled with a development build of Mole on September 17, 2026. Preferences were removed by the cask's zap step; ~/.config/wireshark had not been written on the test machine, so its review-only handling was not exercised by that removal. ChmodBPF was uninstalled through brew's own uninstall stanza rather than through anything Mole did directly. The official DMG's bundled Uninstall ChmodBPF.pkg was not tested through Mole; the description above of what it does comes from reading Wireshark's own installer scripts, not from a recorded Mole uninstall on that channel.

    If Mac apps leave files behind after uninstalling, try Mole. I've personally tested and inspected 799 Mac apps.

    Try Mole

    Mole · 鼴

    Cleanup, software, and status for your Mac.

    v1.16.0 (304) · Release notes

    Product

    Mac Cleaner App Uninstaller Mac Optimizer Disk Analyzer System Monitor

    Support

    Help Documentation Releases Blog

    Legal

    Terms of Service Privacy Policy Refund Policy

    Resources

    CLI Tool Affiliate Program

    Connect

    Twitter hi@mole.fit

    Mole’s only official website mole.fit · Avoid installers from unknown sources

    The CLI stays free for terminal workflows.