Apple Rushes Out Patches for macOS Screen-Sharing Flaw That Bypasses Login
Published on 08/09/2026 at 15:21 | Redaktion boerse-global.de
A security hole in Apple's remote-access tool could let someone on the same Wi-Fi network seize control of a Mac without ever typing a password. The company responded with emergency updates on August 6, skipping its usual public beta cycle — a strong signal of how seriously it took the threat.
The vulnerability, catalogued as CVE-2026-65400, lives in the screen-sharing service built into macOS. Attackers who were already connected to the same local network or wireless connection could tamper with the authentication flow and gain full command of the graphical interface on the target machine. No credentials required.
What made the flaw especially dangerous was the privilege level attached to the affected component. The process known as SSFileCopySender operated with root access and full disk permissions. That combination opened the door to remote code execution — meaning an intruder could run arbitrary malicious software from afar — and also exposed sensitive system files. The severity rating sits at 7.5 on the CVSS scale, underscoring how much damage a successful exploit could inflict.
Apple has now shipped fixes for three macOS generations at once:
- macOS 26.6.1 (Tahoe)
- macOS 15.7.9 (Sequoia)
- macOS 14.8.9 (Sonoma)
Users can pull the patches down through System Settings under the "Software Update" pane. There is no evidence so far that the vulnerability has been actively exploited in the wild, but security researchers are urging people not to sit on the update.
Environments where screen sharing is used heavily — or where many machines sit on the same network — face the highest exposure. Public Wi-Fi hotspots and corporate networks with weak segmentation also raise the stakes considerably. Whether an attacker could reach the flaw over the internet rather than just a local connection is still under investigation.
Any security gap in your digital systems deserves the same urgent attention you give to physical workplace hazards. A free toolkit with 41 ready-to-use templates and checklists helps you document and manage risks across fire safety, manual handling, and lone working — so you can stay ahead of compliance issues before they become problems. Download the free Risk Assessment Toolkit
Meanwhile, Apple is already testing iOS 26.6.1 in parallel. In Europe, the rollout of certain Siri AI features continues to be held up by the Digital Markets Act. For administrators juggling multiple priorities, the broader security picture matters too: cloud-stored data in services like Dropbox deserves scrutiny, and removing office software suites carries its own risks, including the possibility of losing data in the process.
