Apple urges Mac users to install urgent Screen Sharing security update
Apple has patched a macOS Screen Sharing flaw that could bypass authentication, urging affected Mac users to update promptly.
Apple has released a series of macOS security updates to address a vulnerability that could allow an attacker to bypass authentication for the operating system’s built-in Screen Sharing feature. The flaw affects several supported versions of macOS and could allow an attacker to access a Mac without requiring valid login credentials.
Table Of Content
The vulnerability, identified as CVE-2026-65400, is addressed in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Apple has released the updates outside its usual major software release cycle, making the patch particularly notable for Mac users and organisations that rely on remote-access features.
The vulnerability affects Mac Screen Sharing
Screen Sharing is a built-in macOS feature that allows another user to view and control a Mac remotely. Depending on how it is configured, remote access can provide visibility of the desktop, files, open applications and windows. It can also allow a connected user to perform actions such as restarting the computer.
The authentication bypass therefore presents a more serious risk than a flaw affecting a feature with limited access to the system. If successfully exploited, the vulnerability could allow an attacker on the same network to access Screen Sharing without supplying the credentials normally required to connect.
Apple says the vulnerability affects only users who manually enabled Screen Sharing before installing the security update. An attacker would also generally need to be connected to the same network as the targeted Mac. This significantly reduces the likelihood that the vulnerability will be exploited remotely over the internet.
Home and business networks may also provide additional protection by blocking the connections required to carry out an attack. However, the limitation does not eliminate the risk, particularly for Macs used on shared, workplace, or otherwise less-trusted networks.
The vulnerability was reported by Alfredo Pesoli, co-founder and chief executive of cybersecurity company Bynario. Apple has said it is not aware of the flaw being exploited outside testing environments. An Apple spokesperson also told Inc. that Mac users who have not manually enabled Screen Sharing are not affected.
There is currently no publicly available proof-of-concept exploit for CVE-2026-65400. While the lack of known attacks and public exploit code provides some reassurance, security researchers still recommend applying the available patches rather than relying on those circumstances to remain unchanged.
Apple issued the fix outside its usual schedule
The timing of the updates has drawn attention because Apple released them separately from its larger software update cycle. The company’s security documentation lists CVE-2026-65400 as the vulnerability addressed by these releases, highlighting the importance Apple has placed on resolving the issue.
Phil Stokes, a research engineer at cybersecurity company SentinelOne, told Inc. that the timing “suggests some urgency.” He also said organisations should treat the update as a patching priority depending on whether Screen Sharing is enabled and accessible on their systems.
The risk is likely to be more relevant to businesses and other organisations that use Macs with remote access enabled. A compromised device could expose information available through the remote desktop session, making systems used for sensitive work particularly important to update promptly.
For individual Mac owners, installing the fix does not require any complicated security configuration. Users can open System Settings, select General and then choose Software Update. The available update can then be installed if the Mac is running one of the affected versions of macOS.
Apple has consistently recommended keeping its operating systems up to date as an important part of maintaining device security. Applying security updates can help protect against vulnerabilities after fixes become available, even when there is no evidence that a particular flaw is currently being exploited.
The patch arrives before Apple’s next major software releases
The security update comes as Apple prepares for its next generation of major operating system releases. The company is expected to introduce macOS 27 and iOS 27 later this year, bringing broader software changes and new features to compatible devices.
Those larger releases are likely to attract considerably more attention because of features such as expanded artificial intelligence capabilities and new on-device intelligence functions. However, users should not overlook smaller security releases while waiting for the next major version of macOS.
The Screen Sharing flaw is particularly relevant because the feature can grant extensive control over a Mac once a remote connection is established. Although the attack requires specific conditions, including Screen Sharing being manually enabled and the attacker generally being on the same network, an authentication bypass can still create an unnecessary security exposure.
PoC for a critical vulnerability in Apple macOS Screen Sharing (CVE-2026-65400).
— Calif (@calif_io) August 8, 2026
If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.
We reverse engineered Apple’s unusual macOS 26.6.1 patch to understand… pic.twitter.com/WRIIwKx6yI
Installing macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 or macOS Sonoma 14.8.9, depending on the Mac and operating system version, removes the vulnerability addressed by Apple’s latest security releases. Users who have Screen Sharing enabled have the strongest reason to install the update without delay.
The absence of known attacks does not guarantee that the vulnerability will remain unused. Once security flaws become publicly documented and patches are available, researchers and attackers can examine the changes to identify ways to reproduce the underlying issue. Updating promptly therefore gives Mac users a straightforward way to reduce their exposure before the vulnerability becomes a more practical target.







