Secretus logo

macOS Screen Sharing Auth Bypass: Patch CVE-2026-65400

·7 min read

Apple has shipped out-of-band macOS updates for a Screen Sharing authentication flaw that could let an attacker on the network connect without valid credentials. The vulnerability is tracked as CVE-2026-65400 and affects the three currently supported macOS release lines.

Apple released macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 on August 6, only ten days after the preceding security releases. Apple says it corrected an authentication issue with improved state management. The company has not published a CVSS score, exploit details or a statement that the flaw was used in the wild. Those omissions matter: this is an urgent network authentication bypass, but it should not be described as a confirmed zero-day campaign without evidence.

Affected and fixed macOS versions

The CVE record lists every earlier version in these supported branches as affected:

  • macOS Tahoe before 26.6.1
  • macOS Sequoia before 15.7.9
  • macOS Sonoma before 14.8.9

A Mac is not safe merely because it installed Tahoe 26.6, Sequoia 15.7.8 or Sonoma 14.8.8 in late July. Those versions predate this fix. Administrators should verify the full patch number after installation and reboot, rather than relying on a device reporting that it is on a generally supported major release.

What the Screen Sharing flaw means

Apple's wording is narrow: an attacker “on the network” may be able to authenticate to Screen Sharing without valid credentials. That describes a failure at the authentication boundary, not simply a crash or information leak. A successful connection could expose whatever the Screen Sharing session allows the remote party to see or control under the target Mac's configuration.

The phrase “on the network” does not automatically mean the same physical Wi-Fi. It can include a reachable corporate segment, VPN, flat office network, exposed remote-access path or a hostile device already inside the environment. Internet exposure depends on routing, firewall and port-forwarding rules. The first defensive question is therefore reachability: which systems can initiate a Screen Sharing connection to each Mac?

Apple credits Alfredo Pesoli via Bynario Atlas for the report. No public proof of concept is required to make the risk meaningful. Authentication code is exactly where defenders should prefer patching over guessing whether a specific state transition can be reproduced.

Who should treat this as highest priority

  • Macs with Screen Sharing or Remote Management enabled.
  • Developer workstations holding source code, signing material or cloud sessions.
  • Shared office, university, hospitality or lab networks with weak client isolation.
  • Fleet Macs reachable through VPNs, jump hosts or remote-support networks.
  • Systems for which VNC or Screen Sharing ports were forwarded through a firewall.

A Mac with Screen Sharing disabled and no reachable service has less immediate exposure, but installing the update remains the durable fix. Configuration drifts, support tools re-enable remote management, and laptops move between networks.

Enterprise response checklist

  1. Deploy the correct update. Require Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9 across compatible devices.
  2. Verify after reboot. Collect the installed product version and build through MDM; do not count an update command as proof of completion.
  3. Inventory remote access. Check whether Screen Sharing, Remote Management or legacy VNC compatibility is enabled and whether policy requires it.
  4. Restrict reachability. Permit management traffic only from dedicated support networks or approved jump hosts, not entire user or VPN ranges.
  5. Review exposure. Remove public port forwarding and inspect VPN, security-group and local firewall rules that make the service reachable.
  6. Investigate unexpected sessions. Preserve authentication, endpoint and network telemetry before changing a Mac that shows unexplained Screen Sharing activity.

Do not confuse it with the earlier VNC root-RCE report

CVE-2026-65400 is a new authentication-bypass issue fixed in the August 6 point releases. It is separate from CVE-2026-43760, an earlier Screen Sharing and legacy VNC file-transfer vulnerability that could lead to root-level code execution under a different set of prerequisites. Similar components and close disclosure dates do not make the bugs interchangeable.

That distinction changes both detection and remediation. For this new issue, the reliable source of truth is Apple's August point release and the version running on the device. Disabling unused remote access reduces exposure, but only the patched release closes the vulnerable authentication path Apple identified.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus