On this page
Before downloading, use “About This Mac” to identify Apple Silicon or Intel
Open “About This Mac” from the Apple menu. If Chip says Apple M1, M2, M3, or a later Apple series, choose the Apple Silicon / arm64 build. If Processor says Intel, choose the x64 / Intel build. Used and managed devices do not always follow assumptions based on purchase year, so system information is the most reliable source.
Download the macOS asset from the Release page of the actual project, such as Clash Verge Rev; the file list should match the version tag and release notes. Do not use a similarly named “cracked Mac edition” from a file-sharing site or assume a file is maintained merely because Clash appears in its name.
Mac and asset labels
| What the Mac reports | Option |
|---|---|
| Apple M-series chip | arm64 / Apple Silicon |
| Intel processor | x64 / Intel |
| Universal | Contains both architectures and is usually larger |
| Unable to determine | Return to “About This Mac” and check instead of guessing |
A DMG is only installation media; drag the app into Applications
Standard installation process
Open the downloaded DMG
Wait for Finder to show the app icon and Applications folder.
Drag the app into Applications
After copying finishes, launch it from the Applications folder; do not keep running it from the DMG.
Eject the disk image
Once the app is copied, eject the DMG from the Finder sidebar.
Keep the original Release information
You will need the version and architecture later for troubleshooting and updates.
If an older version with the same name already exists in Applications, completely quit its menu bar process before replacing it. An old ClashX instance, another Mihomo client, or VPN software may alternately change the system proxy and make the new installation look broken.
Handle “developer cannot be verified” under Privacy & Security
When macOS first opens an app downloaded from the internet, it may say the developer cannot be verified or the app was blocked. Recheck the project Release, version, and filename, then open “System Settings > Privacy & Security,” find the recently blocked item, and follow the system's “Open Anyway” flow.
Do not run a global command that disables Gatekeeper or install an unknown signing patch to bypass the prompt. A per-app exception from the system is sufficient, while other downloads remain protected. If the app is reported as damaged, redownload the asset for the correct architecture instead of immediately removing security attributes.
After the menu bar icon appears, wait for the core status to stabilize
An interface on first launch does not mean Mihomo is ready. Open settings or logs and confirm that the core is not repeatedly exiting and that the client can read and write its configuration directory. No subscription has been imported yet, so any core failed or permission denied message belongs to the local installation layer.
If the app opens only after a Rosetta prompt, you probably chose an Intel build. Although Apple silicon can run some Intel apps, use the project's arm64 version to reduce extra dependencies and avoid confusion during future updates.
For the first configuration, use only the subscription and system proxy
On the Profiles screen, add a Clash- or Mihomo-compatible subscription, update it manually, and select it. Open Proxies, pin one node, keep the mode on Rule, then enable System Proxy. macOS may request permission to change the system proxy; the requesting app should be the client you just installed.
When the browser opens a familiar site, the corresponding connection should appear in Connections. Do not enable TUN or install a network extension until the ordinary system proxy works. Otherwise, one failure will involve the subscription, node, system proxy, and network permissions at once.
Visible results of the first connection
- The Profile shows the current update time
- You can select a specific node in Proxies
- The current client writes the macOS system proxy
- Connections shows the browser request you just made
An app that will not open and a web page that will not open are separate troubleshooting paths
The app icon has a prohibited symbol
Check the macOS version requirement and app architecture, then download the matching build.
The app says it is damaged
Redownload it from the original Release and confirm that the file is complete and from the same source.
Subscription update returns 401 / 403
The link credential or account status has a problem unrelated to macOS permissions.
The browser fails and Connections is empty
Confirm that System Proxy was written, and quit other proxy clients.
The connection enters Clash but shows timeout
Switch to another verified node; there is no need to reinstall the DMG.
Return to the layer corresponding to the first screen where the error appears. Only after the app starts, the Profile updates, and a node can be selected should a web connection failure send you to proxy and rule troubleshooting.
Before uninstalling or switching clients, restore direct networking on macOS
Before uninstalling, rolling back, or migrating to another client, disable the system proxy and TUN in the current app and quit completely from the menu bar. Closing only the window can leave a background process listening on the local proxy port. Dragging the app directly to Trash then leaves web requests pointing to an address with no listener.
In macOS network settings, confirm that HTTP, HTTPS, and SOCKS proxies have been removed; the browser should directly reach locally accessible sites. After direct access returns, delete the app from Applications and remove data you no longer need. During migration, reimport the subscription instead of overwriting one client's data directory with another's.
After the new client enables System Proxy, a new browser request in Connections proves that stale proxy state is gone. This Mac has now completed its first setup from architecture selection and app installation through Gatekeeper approval, subscription import, and the system proxy. For future version changes, repeat the same quit and direct-access checks.
