Screen Sharing Bypass Lets Attackers Log In Without Credentials

The break is in Screen Sharing’s login logic, not in macOS itself. If the service loses track of auth state, a network request can be accepted as already vetted, so changing passwords does not fix the weakness on its own. Apple fixed CVE-2026-65400 in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. NCSC-NL says the flaw let remote attackers gain access without valid credentials because state management during authentication was insufficient, and Apple tightened that validation so only legitimate logins are accepted.

Part of the PlainSec briefing for 2026-08-08

Every edition of this story: Screen Sharing Bypass Lets Attackers Log In Without Credentials

Sources