Advertisement
News

Apple Patches a macOS Screen Sharing Flaw That Bypassed Password Checks

Aditya Singh

Apple has pushed out an unscheduled round of macOS security updates that close a single flaw in Screen Sharing — one that let an attacker on the same network authenticate to a Mac without a valid password. The fix ships as macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9, and it is available worldwide right now.

The vulnerability is tracked as CVE-2026-65400. Apple describes it as an authentication issue and says it was resolved through improved state management. There is no indication it was used against anyone before the patch landed.

An open MacBook Pro on a white desk beside a notebook, ruler and pencil
Every Mac running macOS Sonoma, Sequoia or Tahoe has an update waiting in Software Update.

What the flaw actually allowed

Screen Sharing is the built-in macOS service that lets another machine view and control your desktop. The bug meant that someone already on your network could get past the credential check and reach that service anyway. Depending on how the Mac was configured, that could mean watching the screen, opening apps and files, or acting on the machine as though they were sitting in front of it.

Two details are worth holding onto, because they set the real severity. First, the attacker has to be reachable on the network — this is not something a random person on the open internet could fire at any Mac. Second, no exploitation in the wild has been reported. This is a fix that arrived before the problem did, which is the order you want.

The flaw was reported by security researcher Alfredo Pesoli, working with Bynario Atlas.

Advertisement

The exact versions and builds

Apple patched all three currently supported macOS branches in parallel, so there is no reason to upgrade to a newer major release just to get the fix:

  • macOS Tahoe 26.6.1 — build 25G76
  • macOS Sequoia 15.7.9 — build 24G830
  • macOS Sonoma 14.8.9 — build 23J631

Every Mac capable of running one of those three versions is covered. Notably, none of these builds went through developer or public beta testing first — Apple shipped them straight to release, which it tends to do only when a security fix is the entire point of the update. They also arrive barely a week after the much larger macOS Tahoe 26.6 round, which carried well over a hundred CVE fixes and landed alongside the iOS 26.6 security update.

How to install it

The update is small and does not change any features. To install it:

  • Open System Settings.
  • Go to General > Software Update.
  • Wait for the check to finish, then install the update offered for your macOS version.

To confirm it applied, open the Apple menu, choose About This Mac, and click the version number to reveal the build. It should read 25G76, 24G830 or 23J631 depending on which branch you are on. Apple has published the technical write-up on its macOS Tahoe 26.6.1 security page.

Check whether Screen Sharing is even on

Most people never switch Screen Sharing on, and it is off by default. It is still worth a look while you are in System Settings — go to General > Sharing and check both Screen Sharing and Remote Management. If neither is enabled, your exposure to this particular bug was minimal regardless.

That is not a reason to skip the update. Apple recommends it for all users, and a machine that is patched today cannot be caught out by someone flipping the service on later, or by a shared Mac where someone else already did. Security fixes for Apple platforms have been arriving faster and in tighter batches through 2026 — a pattern that was also visible in how quickly Apple moved on the DarkSword iOS exploit.

If your Mac has automatic updates enabled, it will pick this one up on its own within a day or so. If you have that switched off, this is a good week to install it by hand.

Frequently Asked Questions

What does macOS Tahoe 26.6.1 fix?

It fixes CVE-2026-65400, an authentication flaw in Screen Sharing. An attacker on the same network could authenticate to the service without valid credentials, potentially viewing the screen or controlling the Mac. Apple resolved it through improved state management.

Which macOS versions received the security update?

Three branches were patched at the same time: macOS Tahoe 26.6.1 (build 25G76), macOS Sequoia 15.7.9 (build 24G830) and macOS Sonoma 14.8.9 (build 23J631). Every Mac running one of those releases is covered, so there is no need to move to a newer major version to get the fix.

Was the Screen Sharing vulnerability exploited?

No evidence of exploitation in the wild has been reported before the patches shipped. The flaw was disclosed by security researcher Alfredo Pesoli working with Bynario Atlas, and Apple fixed it ahead of any known attacks.

Do I need the update if I never use Screen Sharing?

Apple recommends the update for all users. Screen Sharing is off by default, so if you never enabled it your exposure was minimal, but installing the patch protects you if the service is ever switched on later or by someone else sharing the Mac.

How do I check which macOS build I am running?

Open the Apple menu, choose About This Mac, then click the version number to reveal the build string. Install the update from System Settings under General and Software Update if you are not already on 25G76, 24G830 or 23J631.

AppleMacSecurityCybersecurityTech News

Related Articles

Advertisement