CA

Java class / Mach-O fat file signature

Magic number at the start of the file

CA FE BA BE

The bytes CA FE BA BE (the readable word cafebabe) are a famous collision: they begin both a compiled Java .class file and a Mach-O universal (fat) binary on macOS.

Hex signature
CA FE BA BE
Offset
0 (start of file)
Length
4 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes CA FE BA BE, it is a Java class / Mach-O fat file.

They are distinguished by what follows. In a Java class the next four bytes are the minor and major version (for example 00 00 00 34 for Java 8). In a Mach-O fat binary the next four bytes are a plausible architecture count, and each slice inside is a normal Mach-O starting feedface or feedfacf.

What each byte of CA FE BA BE means

Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.

Byte offsetHexDecimalASCII
0CA202.
1FE254.
2BA186.
3BE190.

Formats that use the CA FE BA BE signature

No extension in our database is documented under this signature: the bytes belong to the Java class / Mach-O fat format itself, which usually appears as a wrapper around something else. Files that carry it are normally named CLASS, Mach-O universal binary.

How to check a file's signature

You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.class
  • hexdump -C -n 16 example.class
  • file example.class

Windows (PowerShell)

  • Format-Hex -Path example.class -Count 16

Python

  • open("example.class","rb").read(4).hex()

In your browser

Frequently asked questions

What is the Java class / Mach-O fat file signature?

Java class / Mach-O fat files start with the hex bytes CA FE BA BE. This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.class on Linux or macOS, or Format-Hex -Path example.class -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the Java class / Mach-O fat signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine Java class / Mach-O fat file has these exact bytes; a file with the wrong bytes is not really Java class / Mach-O fat, whatever its name says.

Related signatures

Sources

Reuse this signature

This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.