CVE-2026-65400
9.5 CISA KEVApple · macOS
An improper authentication flaw in Apple macOS Screen Sharing allows unauthenticated network attackers to bypass credentials and gain remote access.
Executive summary
A critical authentication bypass in Apple macOS Screen Sharing is currently being exploited in the wild by remote attackers.
Vulnerability
The vulnerability exists within the Screen Sharing component, where an attacker on the network can authenticate without providing valid credentials (CWE-287). This flaw is remotely exploitable without requiring user interaction.
Business impact
With a CVSS score of 9.5, this vulnerability presents a high risk of unauthorized remote control over affected macOS devices. Successful exploitation could lead to full system compromise, the theft of sensitive local files, and the potential for lateral movement within the network.
Remediation
Immediate Action: Apply the latest security updates provided by Apple to update macOS to the specified patched versions.
Proactive Monitoring: Review system logs for unauthorized Screen Sharing sessions and monitor network traffic for connections attempting to bypass standard authentication protocols.
Compensating Controls: Disable Screen Sharing services if they are not required for business operations, and restrict access to these services via local firewall rules to trusted networks only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
This is a critical security issue that requires immediate attention due to confirmed active exploitation. Administrators should ensure all macOS endpoints are updated to the secure versions without delay to prevent unauthorized remote access.