All stories
Big Tech

Apple issues urgent macOS security updates for critical Screen Sharing vulnerability

Apple has rapidly deployed crucial security updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, bypassing typical beta cycles to address a serious Screen Sharing vulnerability (CVE-2026-65400) that could allow unauthorized local network access and full system control.

By TECH NEWS Editorial·Source:Engadget·3 min read·2h ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Apple issues urgent macOS security updates for critical Screen Sharing vulnerability

Apple has swiftly released crucial security updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, directly addressing a serious Screen Sharing vulnerability (CVE-2026-65400) that could allow an attacker on the local network to authenticate without valid credentials. This rapid deployment, notably bypassing typical beta cycles, underscores the critical nature of the flaw, which permits unauthorized access to a Mac's screen and potentially full system control, including the ability to read and write files as root, all without requiring a password or user interaction. The vulnerability, identified by Alfredo Pesoli via Bynario Atlas, is rooted in an authentication issue within the `screensharingd` daemon, specifically a mishandling of oversized data frames that could deceive the system into bypassing password checks and establishing a fully privileged, unencrypted session.

The immediate impact on users is substantial, particularly for those who have Screen Sharing enabled, despite the feature being off by default. For individuals and businesses that rely on remote access or collaboration tools utilizing Screen Sharing, this vulnerability represents a direct pathway for data exfiltration, espionage, or even complete system compromise by an attacker already present on the local network. While there is no indication that the bug has been exploited in the wild, the potential for a sophisticated local network attack, capable of establishing a root shell in under 60 seconds according to researchers' tests, makes these updates imperative. The significant size of these updates for the three major macOS versions—Sonoma, Sequoia, and the recently introduced Tahoe—ranging from 1.5 to 2.1 GB, suggests that the fix involves more than a minor code adjustment, likely touching fundamental frameworks related to authentication and state management within the Screen Sharing service.

This incident highlights Apple's evolving approach to security patching. Historically, Apple has sometimes bundled security fixes with larger feature updates, but recent trends indicate a clear shift towards more frequent, targeted security releases. This particular update marks the second round of macOS updates in less than two weeks, following macOS 26.6, which was released on July 27 and also contained security fixes. This increased cadence demonstrates Apple's commitment to reducing the time between vulnerability discovery and patch deployment, a crucial strategy in an era of escalating cyber threats. By forgoing public betas for these critical patches, Apple prioritizes user safety over the traditional testing pipeline, a decision that speaks volumes about the perceived severity of the Screen Sharing flaw.

Compared to its rivals, Apple's security posture is generally considered robust, characterized by a strong emphasis on privacy and secure hardware-software integration. However, no ecosystem is impenetrable, and complex features like Screen Sharing, which allow deep system interaction, often present attractive targets for attackers. Major operating systems such as Windows and various Linux distributions also face a constant barrage of vulnerabilities, necessitating regular patch cycles and emergency updates. The key differentiator often lies in the speed and transparency of disclosure and remediation. Apple's prompt action here, detailing the vulnerability and its fix shortly after the update's release, aligns with best practices in responsible disclosure.

Looking ahead, the increasing sophistication of cyberattacks, coupled with the pervasive use of remote access functionalities in both professional and personal environments, means that vulnerabilities like CVE-2026-65400 are likely to remain a significant concern. Apple's accelerated patching schedule is a pragmatic response, but it also signals a heightened threat landscape where even fundamental system services can harbor critical flaws. The recent overhaul of Apple's bug bounty program, announced just two days prior to these macOS updates, further indicates the company's proactive stance in incentivizing security researchers to uncover and report vulnerabilities before malicious actors can exploit them. Users, in turn, must embrace the "new normal" of more frequent security updates, ensuring their systems are always current to mitigate risks effectively. The ongoing development of macOS, with upcoming versions like macOS 27 already in public beta, will undoubtedly continue to integrate advanced security mechanisms, but the foundational principle of timely patching will remain paramount for protecting the vast ecosystem of Apple devices.

Sources