Apple has released security updates for all three major versions of macOS that are currently supported, patching a serious vulnerability in Screen Sharing. The updates were made available earlier today as macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. In their initial release notes, Apple only said that the updates provided important security fixes and were recommended for all users. Now, the company has updated its security releases page with more detailed information, and the headline fix is a Screen Sharing issue that could allow an attacker on the local network to log in without valid credentials.
The vulnerability is listed under the Screen Sharing component in Apple’s security documentation. According to the advisory, an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. This type of flaw is particularly serious because Screen Sharing is designed to allow remote access to a Mac’s desktop session. Apple says the authentication issue was addressed with improved state management, a common way to close logical flaws in login and session handling.
The bug is tracked as CVE-2026-65400 and was discovered by Alfredo Pesoli, also known as @__rev, working through Bynario Atlas. Apple’s advisory does not include any information suggesting that the vulnerability was exploited in the wild before the update was released. However, the company still decided to ship fixes outside of its normal release cadence, which signals that it considered the issue severe enough to warrant an urgent response.
Apple’s latest macOS versions include macOS Tahoe, which is this year’s major release, alongside macOS Sequoia and macOS Sonoma. The company chose to patch all three operating systems simultaneously, appearing to provide broad coverage for users who have not updated to the newest version. This is a reminder that macOS updates are not only about new features; they also include important security fixes for vulnerabilities that could be exploited by malicious actors.
What is Screen Sharing?
Screen Sharing is a built-in macOS service that allows a user to connect to another Mac over a network and control its interface. It is widely used by system administrators, IT teams, and users who need to access their home computer while away. The feature is based on the VNC protocol, and Apple has integrated it into the operating system so that it can be used without installing additional software. When enabled, Screen Sharing can allow remote users to view the desktop, move the mouse, open applications, and transfer files, depending on the permissions granted to the session.
Because Screen Sharing exposes a listening service on the network, it has historically been an attractive target for attackers. If authentication can be bypassed, an attacker may gain full remote control of a computer without needing a password. This can lead to stolen files, unauthorized access to email and other accounts, installation of malware, and in worse cases, deep compromise of the entire system. The vulnerability addressed in this update fits into that category, as it removes the need for credentials when connecting from the network.
Potential impact
An attacker who is able to authenticate to Screen Sharing without valid credentials could potentially view a vulnerable Mac’s screen and control it. The exact level of access depends on how the Mac is configured. In many cases, Screen Sharing is either enabled for all users or for users with administrator rights. If an attacker connects with administrative privileges, they might be able to access sensitive files, install software, and create new user accounts. This level of control means that the impact of the vulnerability could be significant for individuals and organizations.
Additionally, Screen Sharing can remain enabled for reasons that are not immediately obvious. Sometimes a user enables it to allow a technician to help them troubleshoot, and later forgets to disable it. The feature can also be enabled through older versions of Remote Management or through the Screen Sharing app’s preferences. Even if a user does not actively use Screen Sharing, the service may still be running on the Mac if it was turned on at some point in the past. This is why Apple’s recommendation to install the update applies to all users, not only those who rely on Screen Sharing for remote access.
Why this update matters
The importance of this update is underlined by the fact that Apple released patches for three separate macOS versions on the same day, without a public beta period and without waiting for its next major software release. Security experts often advise users to prioritize operating system updates because vulnerabilities in core services can have a broad impact. The Screen Sharing flaw is especially relevant for Macs on the same local network as other devices, such as on a home Wi-Fi network or corporate office network. An attacker would not need to be running a complex exploit; the advisory describes a flaw in authentication, which can sometimes be triggered simply by interacting with the service’s remote session protocol.
CVE-2026-65400 is also a reminder that Apple continues to rely on external security researchers to find critical bugs. Responsible disclosure programs allow researchers like Alfredo Pesoli to report security flaws to Apple before they become publicly known. Apple then develops and tests a fix, and in this case, the company deployed updates to multiple versions of macOS. The credit in the security advisory helps track and recognize such research work, and it encourages more people to look for vulnerabilities in Apple’s software.
What users should do
Users should update their Macs as soon as possible to protect themselves from the Screen Sharing vulnerability. The update can be installed by opening System Settings, choosing General, and then clicking Software Update. macOS Tahoe, Sequoia, and Sonoma users will see the update listed as macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9, depending on their current operating system. It is usually recommended to back up important data before installing system updates, though this can be done automatically with Time Machine if it has been set up.
Computers that cannot be updated immediately can reduce their risk by disabling Screen Sharing if they do not need it. This can be done in System Settings under General and then Sharing, or in the earlier System Preferences sharing pane. Users can also use the macOS firewall to limit incoming connections and ensure that the Screen Sharing feature is not exposed to the internet. Even with those protections, Apple’s update is the only complete way to close the vulnerability.
In addition to updating, users should review their Mac’s security settings. Enabling the built-in firewall, turning on FileVault encryption, and avoiding public Wi-Fi networks without a VPN are helpful practices. Screen Sharing sessions should only be used when necessary, and credentials should be strong and unique. For organizations, IT administrators should inventory which Macs have Screen Sharing enabled and verify that updates are deployed across all managed devices.
Apple’s security notes continue to be an important resource for users who want to understand what is fixed in each update. The company regularly publishes details about vulnerabilities, their impact, and the researchers who reported them. Today’s release is a clear reminder that timely software updates are one of the most effective defenses against malicious attackers. While this particular vulnerability may not have been used in real-world attacks yet, the risk is real, and users should take action quickly.
Source: 9to5Mac News