Apple released macOS Tahoe 26.6.1 on August 6, and if you use Screen Sharing on your Mac — or have it enabled — you should install this update immediately. It fixes a vulnerability that could let an attacker on your local network access Screen Sharing without providing valid credentials at all.
The flaw, tracked as CVE-2026-65400, is as bad as it sounds. Anyone on the same network as your Mac — a shared office Wi-Fi, a coffee shop hotspot, a college campus network — could potentially authenticate to Screen Sharing without knowing your password. Once in, they would have remote control of your Mac’s desktop, access to your files, and the ability to run applications.
macOS Screen Sharing vulnerability: what Apple fixed
According to Apple’s security advisory, “an attacker on the network may be able to authenticate to Screen Sharing without valid credentials.” Apple addressed the issue with “improved state management” — suggesting the authentication logic had a flaw in how it tracked session states, allowing an attacker to bypass the credential check entirely.
The vulnerability was discovered by security researcher Alfredo Pesoli and reported through Bynario Atlas. Apple has not said whether the flaw was actively exploited in the wild before the fix, which typically means the company has no evidence of exploitation — but that does not mean it hasn’t happened, only that Apple hasn’t confirmed it.
Screen Sharing is built into every Mac and is frequently used for remote support, file transfers, and managing multiple machines. Many users enable it once and forget about it, which makes this kind of authentication bypass particularly dangerous — if you’re not actively using it, you may not even realise someone else is.
Which Macs are affected
The vulnerability affects all three currently supported macOS versions. Apple released fixes for all of them simultaneously:
- macOS Tahoe 26.6.1 (build 25G76) — for Macs running macOS 26
- macOS Sequoia 15.7.9 — for Macs still on macOS 15
- macOS Sonoma 14.8.9 — for Macs still on macOS 14
If your Mac is running any of these three macOS versions, the fix is available right now. If your Mac is too old to run Sonoma 14 or later, it no longer receives security patches from Apple — and this vulnerability likely exists on those machines too, unpatched.
How to install the update
- Open System Settings (click the Apple menu in the top-left corner, then System Settings).
- Go to General > Software Update.
- Your Mac will check for updates. You should see macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 depending on your current version.
- Click Update Now and let it install. A restart will be required.
Disable Screen Sharing if you don’t use it
If you don’t actively use Screen Sharing, you should turn it off entirely — it reduces your attack surface regardless of this specific vulnerability. Go to System Settings > General > Sharing, and make sure Screen Sharing is toggled off. While you’re there, review every other sharing toggle too. Most users don’t need Remote Login, Remote Management, or File Sharing enabled by default.
This update contains no new features — it exists solely to close this security hole. That alone should tell you how seriously Apple is treating it.
Sources: Mactrast, Cult of Mac, MacDailyNews
