Apple Patches Critical Screen Sharing Flaw in macOS Tahoe, Sequoia, and Sonoma
Security updates fix a vulnerability that could allow unauthenticated network attackers to gain remote access to Macs.
Apple has released urgent security updates for three versions of macOS to close a vulnerability in the system's Screen Sharing service. The flaw potentially allows an attacker located on the same network to bypass authentication and gain remote access to a Mac without valid credentials.
According to Apple's release notes, the vulnerability enables a network-based attacker to authenticate to Screen Sharing without the required credentials. To address this risk, Apple issued patches for macOS Tahoe (version 26.6.1), macOS Sequoia (version 15.7.9), and macOS Sonoma (version 14.8.9). The updates, released on August 6, 2026, specifically target the Screen Sharing service under CVE-2026-65400.
The Scope of the Risk
Screen Sharing is a native macOS feature designed to let users control another Mac remotely for troubleshooting or collaboration. Because the feature is disabled by default, the vast majority of Mac users are not immediately exposed to this flaw. Only those who have explicitly enabled the service via System Settings > General > Sharing are susceptible to the exploit.
Why It Matters
Despite the limited attack vector, the implications of the flaw are severe. The ability for an unauthenticated user to observe or control a computer remotely represents a critical security failure. In a corporate or shared network environment—where multiple devices reside on the same local area network (LAN)—this vulnerability could lead to unauthorized system changes or the theft of sensitive data. By bypassing the credential check, an attacker effectively gains the same level of access as a legitimate administrator, turning a trusted internal network into a primary threat vector.
What's Next
Users who utilize Screen Sharing are urged to update their systems immediately to the latest patched versions. While the vulnerability is now addressed in the current releases, administrators in enterprise environments should audit their fleet to ensure that Screen Sharing is only enabled on machines where it is strictly necessary. It remains to be seen if similar authentication bypasses exist in other remote management tools within the macOS ecosystem, though Apple has not indicated further issues at this time.