The vulnerability, tracked as CVE-2026-65400, stems from improper state management within the Secure Remote Password authentication process. By bypassing standard credentials, attackers could gain privileged control over exposed machines. Research from Huntress suggests that tens of thousands of Macs—particularly bare-metal systems hosted in data centers—were potentially vulnerable due to internet-facing port 5900.
Apple released security updates on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to resolve the issue. Experts emphasize that simple password changes or disabling legacy VNC authentication are insufficient to mitigate the risk. Because the exploit occurs prior to standard authentication protocols, users must install the latest system patches or disable the Screen Sharing service entirely until updates are applied.
Comments (0)
No comments yet. Be the first!