Apple has rushed out a rare single-fix macOS update to address a Screen Sharing flaw that could let attackers get past authentication.
Apple released macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9 on August 6, addressing the same vulnerability across all three supported versions.
The flaw, tracked as CVE-2026-65400, affects Screen Sharing and could allow an attacker on the network to authenticate without valid credentials. Apple says it fixed the problem through “improved state management,” according to its security advisory.
Apple credits security researcher Alfredo Pesoli, reporting through Bynario Atlas, with discovering the issue. The company has not said that the vulnerability has been exploited in the wild.
Why the screen sharing bug matters
Screen Sharing is designed to let users remotely view and control a Mac. That makes an authentication failure particularly serious: If an attacker can establish a session without valid credentials, the security boundary protecting remote access can effectively break down.
Apple’s advisory does not explain how the flaw works or specify the network conditions required for exploitation.
Security researchers cited by Forbes describe the issue as potentially more severe. Huntress principal security operations center analyst Ryan Dowd said the vulnerability involves Screen Sharing’s implementation of Secure Remote Password and “ultimately allows pre-authenticated remote code execution on all supported macOS versions.”
That assessment goes beyond Apple’s brief advisory, however, and the company has not publicly confirmed those technical details.
Why Apple moved quickly
Apple typically bundles security fixes into scheduled software releases, but this update shows the company was willing to issue a separate patch when a vulnerability affected a built-in remote access feature.
The company also applied the fix across three supported macOS versions instead of limiting it to the newest release. That approach gives users who remain on Sequoia or Sonoma protection without requiring an immediate operating system upgrade.
For consumers, the update is a reminder that even trusted built-in tools can become security entry points when authentication systems fail. Remote access features are designed for convenience, but they also provide attackers with valuable targets if protections break down.
What Mac users should do
Mac users running Tahoe, Sequoia, or Sonoma should install the latest security update through System Settings > General > Software Update.
Users who do not need Screen Sharing should also review whether the feature is enabled under System Settings > General > Sharing and consider turning it off when it is unnecessary. However, disabling Screen Sharing should not replace installing the update. A patched system protects you if the feature is needed later or accidentally enabled.
Also read: Apple briefly removed Telegram from the App Store over a reported CSAM violation before restoring the app later that day.