What it means
XProtect is Apple's built-in macOS malware protection. Apple's platform security description separates several layers: Gatekeeper and notarization help prevent untrusted software from running, while XProtect can detect, block and remediate known malware. These layers work together and receive updates, but none is a guarantee against all threats.
A real-world example
A friend says a suspicious app must be safe because the Mac displayed no alert. That conclusion is too strong. The app might be newly malicious, deceptive without matching known malware, or have been granted access by the user. An absence of an XProtect warning is not a publisher verification.
What to do
Keep macOS security updates enabled, obtain apps through trustworthy official routes and inspect an unusual permission request. If you suspect compromise, review affected accounts and seek help rather than searching for a command to turn off protections.
The distinction that matters
XProtect is not Gatekeeper: the latter evaluates app-launch trust signals, while XProtect has malware detection and remediation roles. Apple's security explanation describes both, including why a permitted launch and a later detection are different events.
Apple's macOS malware protection overview