If you went looking for automatic password replacement in the Passwords app on macOS 27 Golden Gate, expecting it based on what Apple previewed, you did not miss a setting. The feature simply is not in the release. Here is what was actually promised, what happened to it, and what the Passwords app can do for you right now instead.
What Apple actually promised
Ahead of Golden Gate's release, Apple described a new capability for the Passwords app: using Apple Intelligence, it would identify weak or compromised passwords in your saved credentials, then automatically visit the website in question, change the password there, and save the new one back into Passwords, without you manually visiting the site and doing it yourself. For anyone sitting on a long list of old, reused, or leaked passwords, this was one of the more genuinely useful pieces of the Apple Intelligence rollout being discussed ahead of release, since it addressed a tedious, easy-to-postpone security chore directly.
What actually shipped in macOS 27.0
It isn't there. The feature was removed shortly before Golden Gate's public release on September 14, 2026, and the shipping version of the Passwords app does not include it. This wasn't a bug that slipped through; it was a planned feature that didn't make the cut for the initial release, the same way features sometimes get pulled from any software right before shipping.
The Passwords app in macOS 27.0 still does the things it already did on Tahoe: storing passwords, generating strong new ones, flagging weak or reused passwords for your attention, and autofilling credentials in Safari and supported apps. What it does not do is the automated, visit-the-site-and-change-it-for-you part.
When is it expected now
Based on coverage of what's being tested in the macOS 27.2 beta cycle, automatic password changes are expected to arrive in that release rather than the initial 27.0. macOS 27.2 is itself still in beta as of this writing, with a public release expected toward the end of October 2026. There is no firm commitment from Apple that this specific feature will definitely ship in 27.2 rather than slipping further, but it is the release currently associated with it based on what's visible in testing.
What the Passwords app can do today
Even without the automated piece, the Passwords app on macOS 27 is useful for finding the problem, even if it can't fix it for you yet:
- Open the Passwords app.
- Look for a Security Recommendations section, which flags passwords that are weak, reused across multiple sites, or have appeared in a known data breach.
- Each flagged entry will typically let you jump directly to the site's login or account settings page to change the password manually.
- Use the built-in strong password generator when setting the new one, which Passwords offers automatically in supported fields.
This is more manual than what was promised, but it already does the harder part, identifying which of your dozens or hundreds of saved passwords actually need attention, rather than leaving you to guess.
Handling compromised passwords yourself in the meantime
- Prioritize by exposure, not by how old a password is. A password flagged as appearing in a known breach matters more right now than one that's merely old but never leaked.
- Start with financial and email accounts. Email in particular is often the recovery path for every other account, which makes it worth changing first if it shows up as compromised.
- Turn on two-factor authentication wherever Passwords or the site itself offers it, which reduces how much a single leaked password can actually do even before you get around to changing it.
- Let Passwords generate the replacement rather than inventing one yourself; the built-in generator produces something genuinely strong and saves it directly, which is most of what the automated feature would have done besides the site-visiting part.
A few more questions
Was this feature ever available even in beta? Reporting indicates it was described and discussed ahead of release as part of what macOS 27 would bring, but was removed before the public release shipped. Whether it was briefly present in an early beta build isn't something we can confirm either way.
Does Keychain or iCloud Passwords sync still work normally without this feature? Yes. Removing this specific capability doesn't affect password storage, syncing across your devices, or autofill, all of which work exactly as they did before.
Is there a third-party password manager that already does this? Some dedicated password managers offer their own automated password-rotation features, with varying levels of site compatibility. If this capability is a hard requirement for you right now rather than something you can wait on, checking a dedicated password manager's specific feature set is worth doing rather than waiting on Apple's version.
The short version
- Apple previewed automatic, AI-driven password changes for the Passwords app ahead of macOS 27, but pulled the feature before the public release shipped.
- macOS 27.0's Passwords app still flags weak and compromised passwords; it just doesn't change them for you automatically yet.
- The feature is expected to arrive in macOS 27.2, currently in beta, with no firm confirmation it will make that specific release.
- Use the Security Recommendations list in Passwords now to find what needs attention, and change those manually in the meantime.