Apple Patches Critical macOS Screen Sharing Authentication Bypass
A high-severity flaw allowed attackers on the same network to remotely access Macs without credentials.
Apple has released emergency security updates for three versions of macOS to close a critical vulnerability in the system's Screen Sharing feature. The flaw allowed an attacker positioned on the same network to bypass authentication and gain remote access to a Mac without providing valid credentials.
The vulnerability, tracked as CVE-2026-65400, was reported by Alfredo Pesoli via Bynario Atlas. To resolve the risk, Apple issued updates for macOS Tahoe (26.6.1), macOS Sequoia (15.7.9), and macOS Sonoma (14.8.9). According to an Apple Security Note, the flaw meant "an attacker on the network may be able to authenticate to Screen Sharing without valid credentials." Apple stated it addressed the issue by improving state management within the authentication process.
The Risk of Remote Access
Screen Sharing is a native macOS utility designed to let users remotely control another Mac for collaboration or technical support. Under normal operation, this requires strict authentication to ensure only authorized users can view the screen or interact with the system. However, because CVE-2026-65400 allowed for a complete authentication bypass, it effectively removed the primary security barrier protecting the machine. For any Mac with the feature enabled on a local network, this flaw potentially granted attackers the ability to view private screens, open sensitive files, and execute system actions.
Why the Emergency Release Matters
The speed and scope of the rollout signal a high-severity risk. Apple patched three different operating system versions simultaneously without the usual beta testing cycle, a move typically reserved for critical security threats. In the hierarchy of cybersecurity risks, an authentication bypass is among the most dangerous vulnerabilities because it grants an intruder the same level of access as a legitimate user without requiring a password or stolen token. This makes the vulnerability particularly potent in corporate or shared network environments where multiple devices are connected to the same infrastructure.
Next Steps for Users
Mac users on the affected versions of Tahoe, Sequoia, and Sonoma are urged to install the latest updates immediately to secure their systems. While the technical fix focuses on state management during the login process, the most effective immediate mitigation for those unable to update is to disable Screen Sharing in System Settings if it is not actively required. Security researchers will continue to monitor for any signs of the flaw being used in active attacks, though the primary focus remains on widespread patching to eliminate the attack vector.