The world`s foremost network protocol analyzer for Mac

Wireshark for Mac

Wireshark 4.4.1

  -  65.8 MB  -  Open Source

Sometimes latest versions of the software can cause issues when installed on older devices or devices running an older version of the operating system.

Software makers usually fix these issues but it can take them some time. What you can do in the meantime is to download and install an older version of Wireshark 4.4.1.


For those interested in downloading the most recent release of Wireshark for Mac or reading our review, simply click here.


All old versions distributed on our website are completely virus-free and available for download at no cost.


We would love to hear from you

If you have any questions or ideas that you want to share with us - head over to our Contact page and let us know. We value your feedback!

  • Wireshark 4.4.1 Screenshots

    The images below have been resized. Click on them to view the screenshots in full size.

    Wireshark 4.4.1 Screenshot 1
  • Wireshark 4.4.1 Screenshot 2
  • Wireshark 4.4.1 Screenshot 3
  • Wireshark 4.4.1 Screenshot 4

What's new in this version:

The following vulnerabilities have been fixed:
- wnpa-sec-2024-12 ITS dissector crash
- wnpa-sec-2024-13 AppleTalk and RELOAD Framing dissector crashes

The following bugs have been fixed:
- Refresh interface during live-capture leads to corrupt interface handling
- Media type "application/octet-stream" registered for both Thread and UASIP
- Extcap toolbar stops working when new interface is added
- Decoding error ITS CPM version 2.1.1
- Build error in 4.3.0: sync_pipe_run_command_actual error: argument 2 is null but the corresponding size argument 3 value is 512004 [-Werror=nonnull] Issue 19930.
- html2text.py doesn’t handle the <sup> tag
- Incorrect NetFlow v8 TOS AS aggregation dissection
- The Windows packages don’t ship with the IP address plugin
- O_PATH is Linux-and-FreeBSD-specific
- Wireshark 4.4.0 doesn’t install USBcap USBcapCMD.exe in the correct directory
- OER dissector is not considering the preamble if ASN.1 SEQUENCE definition includes extension marker but no OPTIONAL items
- Bluetooth classic L2CAP incorrect dissection with connectionless reception channel
- Profile auto switch filters : Grayed Display Filter Expression dialog box when opened from Configuration Profiles dialog box
- Wireshark 4.4.0 / macOS 14.6.1 wifi if monitor mode
- TECMP Data Type passes too much data to sub dissectors
- Wireshark and tshark 4.4.0 ignore extcap options specified on the command line
- Cannot open release notes due to incorrect path with duplicated directory components
- Unable to open "Release Notes" from the "Help" menu
- No capture interfaces if Wireshark is started from command line with certain paths
- Wireshark 4.4.0 extcap path change breaks third party extcap installers
- Fuzz job UTF-8 encoding issue: fuzz-2024-09-10-7618.pcap
- Unable to create larger files than 99 size units
- Opening Wireshark 4.4.0 on macOS 15.0 disconnects iPhone Mirroring
- PRP trailer not shown for L2 IEC 61850 GOOSE packets in 4.4.0 (was working in 4.2.7) Issue 20088.
- GUI lags because NetworkManager keeps turning 802.11 monitor mode off
- Error while getting Bluetooth application process id by <shell:ps -A | grep com.*android.bluetooth> Issue 20100.
- Fuzz job assertion: randpkt-2024-10-05-7200.pcap

New and Updated Features:
- The TShark syntax for dumping only fields with a certain prefix has changed from -G fields prefix to -G fields,prefix. This allows tshark -G fields to again support also specifying the configuration profile to use.

Updated Protocol Support:
- AppleTalk, ARTNET, BGP, BT L2CAP, CIGI, CIP Motion, CoAP, COSE, DISTCC, DMP, Ethernet OAM PDU, F5 FILEINFO, GIOP, GOOSE, GSM Management, GSM SIM, GTP, HTTP, HTTP2, ID3v2, IDN, IEEE 1609.2, IEEE 802.11, IPPUSB, iRDMA, ISystemActivator, ITS, Kerberos, LwM2M-TLV, MMS, MQ, MySQL, NCP SSS, NetFlow, OER, OWAMP, QNET, RELOAD Framing, RTCP, RTLS, SANE, SMB2, SSyncP, Sysdig Event, T.124, TECMP, Thread, Thrift, and TWAMP

New and Updated Capture File Support:
- BLF, CLLOG, CommView, ERF, and pcap