Apple has issued an unusually targeted macOS update to patch a vulnerability in Screen Sharing that could potentially allow attackers to bypass authentication.
On August 6, the company released macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, with all three updates addressing the same security issue across supported macOS versions.
Tracked as CVE-2026-65400, the vulnerability affects the Screen Sharing feature and could allow a network-based attacker to authenticate without possessing valid credentials. Apple says the issue was resolved through “improved state management,” according to its security advisory.
Apple credited security researcher Alfredo Pesoli, who reported the flaw through Bynario Atlas, for discovering the vulnerability. So far, Apple has not indicated that the issue has been exploited in real-world attacks.
Why the Screen Sharing Bug Matters
Screen Sharing allows users to remotely access and control a Mac, making an authentication flaw in the feature especially concerning. If an attacker can establish a session without legitimate credentials, the protection surrounding remote access could effectively be bypassed.
Apple’s security advisory provides limited technical information about the vulnerability. It does not explain the exact mechanics of the flaw or clarify what network conditions would be necessary for a successful attack.
Security researchers cited by Forbes have suggested that the issue could be more serious than Apple’s advisory indicates. Ryan Dowd, a principal security operations center analyst at Huntress, said the vulnerability affects Screen Sharing’s implementation of Secure Remote Password and could ultimately enable pre-authentication remote code execution across supported macOS versions.
However, that interpretation goes beyond the details Apple has publicly disclosed. The company has not independently confirmed those specific technical claims.
Why Apple Moved Quickly
Apple generally includes security patches in its regular software releases, making this targeted update notable. The company appears to have prioritized a standalone fix because the vulnerability affected a built-in feature designed for remote access.
The patch was also released for three supported macOS versions rather than being limited to the latest release. This means users running macOS Sequoia or Sonoma can address the vulnerability without immediately upgrading to a newer operating system.
For consumers, the update highlights how even trusted built-in features can become potential security entry points when authentication mechanisms fail. Remote access tools offer convenience, but they can also become attractive targets when their security controls are compromised.
What Mac Users Should Do
Mac users running Tahoe, Sequoia, or Sonoma should install the latest available security update by going to System Settings > General > Software Update.
Users who do not rely on Screen Sharing should also check whether the feature is enabled under System Settings > General > Sharing and consider disabling it when it is not needed. However, turning off Screen Sharing should not be considered a substitute for installing the security update.
Keeping macOS fully patched provides protection if Screen Sharing is required in the future or is unintentionally enabled.
Frequently Asked Questions
What is the Mac Screen Sharing vulnerability?
The vulnerability, tracked as CVE-2026-65400, affects macOS Screen Sharing and could allow a network-based attacker to bypass authentication.
Which macOS versions are affected?
The issue was addressed in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
Has Apple confirmed that the flaw was exploited?
No. Apple has not reported evidence that the vulnerability has been exploited in the wild.
How can Mac users protect themselves?
Install the latest macOS security update through System Settings > General > Software Update. Users who do not need Screen Sharing can also disable the feature under System Settings > General > Sharing.
Should I disable Screen Sharing after updating macOS?
If you do not use Screen Sharing, disabling it can reduce your remote-access exposure. However, disabling the feature should not replace installing the security update.
Conclusion
Apple’s latest macOS updates address a serious Screen Sharing vulnerability that could weaken authentication and potentially expose Macs to unauthorized remote access. While Apple has not confirmed exploitation in the wild or disclosed extensive technical details, the issue is significant enough to warrant prompt action.
Mac users should install the appropriate security update as soon as possible, regardless of whether they regularly use Screen Sharing. Those who do not need the feature can also disable it, adding another layer of protection against unnecessary remote-access risks.
