In theory, theory and practice are the same. In theory, all modern macOS applications must be isolated what is enforced by notarization and sandboxing. In practice these enforcements are usually ineffective. This talk starts by explaining basic isolation assumptions and quickly shifts to exploitation. I have selected a few the most popular macOS password managers written in different technologies to prove how a low-privileged malware can abuse various tricks and 0-day, n-day vulnerabilities to drain your credentials. During this talk you will: learn how macOS hardened runtime, sandboxing, and TCC app management privilege work; see 0-day, n-day vulnerabilities and architectonical problems I have found in popular macOS password managers; understand why software distributed via websites is sometimes more secure than from the Apple Mac App Store; see my exploits and a lot of demos.