Apple macOS Improper Authentication Vulnerability

🚨SEVERITY: CRITICAL — CVSS 9.8Security Advisory

TL;DR 📌

  • An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
  • Highest CVSS: 9.8 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Fixed in 14.8.9, 15.7.9, 26.6.1 — upgrade to this release or later.
  • CVEs: CVE-2026-65400.

What it is

CVE-2026-65400 is an authentication bypass in macOS Screen Sharing. Apple describes it as an authentication issue addressed with improved state management. In practice, an attacker on the network can authenticate to Screen Sharing without valid credentials.

The access path is network-based and requires no user interaction and no privileges (AV:N, PR:N, UI:N in the CVSS vector), which is consistent with the description: reaching the flaw only requires network access to a Mac with Screen Sharing enabled, not a valid account on that machine. The impact rating (C:H/I:H/A:H) indicates full compromise of confidentiality, integrity and availability once access is obtained, matching what you’d expect from getting an authenticated screen-sharing session onto someone else’s Mac.

This is listed in CISA’s KEV catalogue, added 18 August 2026, so it is known to be exploited.

What to do

  • Update affected Macs to the fixed releases: macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, or macOS Tahoe 26.6.1, depending on which major version you run.
  • Until patched, disable Screen Sharing (System Settings > General > Sharing) on any Mac reachable from an untrusted network, or restrict access to it via firewall rules limiting which hosts can reach the service.
  • Treat any Mac with Screen Sharing enabled and exposed to an untrusted network segment as a priority for patching, given the KEV listing.
  • After patching, verify the OS build against the versions above rather than relying on “Software Update says up to date” alone, particularly on fleets managed via MDM where update policies may lag.

For leadership 🧭

Executive summary. Any Mac with Screen Sharing turned on and reachable from an untrusted network can be taken over remotely without a password, and this is already being exploited according to CISA’s KEV listing added 18 August 2026. Patch affected Macs immediately or disable Screen Sharing until you can.

Why it matters:

  • A network attacker with no credentials and no user interaction can authenticate to macOS Screen Sharing, effectively bypassing login on any exposed Mac.
  • Once connected, the attacker gets full confidentiality, integrity and availability impact — equivalent to sitting at the machine’s console.
  • The flaw is in CISA’s KEV catalogue as of 18 August 2026, meaning it is known to be exploited, not just theoretical.
  • Macs on shared or untrusted network segments with Screen Sharing enabled (System Settings > General > Sharing) are exposed regardless of local account passwords.

Now / Next / Later:

  • Now: Identify any Mac with Screen Sharing enabled and reachable from an untrusted network, and either disable Screen Sharing or block inbound access to it via firewall rules immediately.
  • Next: Patch all affected Macs to macOS Sequoia 15.7.9, Sonoma 14.8.9, or Tahoe 26.6.1 as appropriate, prioritising machines exposed to untrusted networks given the KEV listing.
  • Later: After patching, verify actual OS build numbers across the fleet rather than trusting Software Update status alone, and review MDM update policies so Screen Sharing-capable Macs aren’t left lagging on security fixes.

Source