Screen Sharing Bypass Lets Attackers Log In Without Credentials
The break is in Screen Sharing’s login logic, not in macOS itself. If the service loses track of auth state, a network request can be accepted as already vetted, so changing passwords does not fix the weakness on its own.
Apple fixed CVE-2026-65400 in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. NCSC-NL says the flaw let remote attackers gain access without valid credentials because state management during authentication was insufficient, and Apple tightened that validation so only legitimate logins are accepted.