What is the CRASH file format?
A .crash file is an Apple crash report generated automatically when an application or system process terminates unexpectedly on macOS, iOS, iPadOS, tvOS, or watchOS. The report captures the process state at the moment of failure, giving developers the information needed to diagnose the underlying bug.
Older .crash files (through macOS 11 Big Sur) are plain UTF-8 text. They begin with a structured header recording the incident identifier (a UUID), hardware model, OS version, process name, exception type, and termination reason. Below the header are per-thread stack backtraces - lists of function-call addresses - followed by a table of all binary images (frameworks and libraries) loaded into the process at crash time, with their memory load addresses and build UUIDs.
Since macOS 12 Monterey (2021), Apple switched the underlying container to the .ips (Incident Progress Stream) format, a JSON object. Files still appear with the .crash extension in Finder and Console.app for backward compatibility, but their content is now structured JSON with keys such as cpuType, osVersion, threads, and binaryImages.
Stack backtraces in unsymbolicated reports show raw hex memory addresses. Converting those to readable function names requires the matching .dSYM debug symbol package for each binary listed in the report. Xcode Organizer symbolicates iOS and tvOS crash reports automatically when the correct .dSYM is available.
On macOS, crash reports are stored in ~/Library/Logs/DiagnosticReports/ for user processes and /Library/Logs/DiagnosticReports/ for system processes. iOS crash logs are retrieved via Xcode Organizer or the ~/Library/Logs/CrashReporter/MobileDevice/ directory.
Security & safety
RISK: LOWCrash report files contain no executable code and pose no security risk on their own. They may contain privacy-sensitive data: username (in file paths), device model, app names, and occasionally argument strings or memory snippets. Apple's diagnostic submission process asks user consent before sending crash reports to Apple.
Format details
in a nutshell- Windows Error Reporting / Generic Crash Dump Reference - Some third-party apps (e.g. Unity, Electron) on Windows also save plain-text crash summaries with a .crash extension, distinct from Apple's format.
Programs that open CRASH files
Technical details
deep spec| Legacy format | Plain UTF-8 text (macOS through Big Sur; iOS through iOS 15) |
| Modern format | JSON object (.ips container renamed .crash for compatibility - macOS 12 Monterey+) |
| Legacy file signature | Incident Identifier: <UUID> header at start of file |
| Modern file signature | { at byte offset 0 (JSON object) |
| Key header fields | Exception type/codes, termination reason, OS version, hardware model, process name and PID |
| Stack traces | Per-thread backtrace of call addresses (symbolicated function names or raw hex) |
| Binary images list | Load addresses and UUIDs of all frameworks and libraries loaded at crash time |
| Symbolication | Raw hex addresses convert to function names using matching .dSYM debug packages |
| macOS storage path | ~/Library/Logs/DiagnosticReports/ (user processes) and /Library/Logs/DiagnosticReports/ (system) |
| iOS retrieval | Xcode Organizer (Crashes tab) or ~/Library/Logs/CrashReporter/MobileDevice/ |
| Platform coverage | macOS, iOS, iPadOS, tvOS, watchOS |
| Typical file size | 10 KB - 500 KB |
| Released | Mac OS X 10.0 (2001); iOS crash reports since iPhone OS 2.0 (2008) |
| Latest version | JSON-based format (macOS 12 Monterey+, 2021) |
| Specification | developer.apple.com |
CRASH conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about CRASH files.