macOS screen sharing flaw let attackers log into Macs without a password on the same network

macOS screen sharing flaw let attackers log into Macs without a password on the same network

N
News Editor
2026-08-08 15:16:33
Apple patched a serious macOS screen sharing authentication flaw, tracked as CVE-2026-65400, on Aug. 6. According to Apple’s security advisory, if Screen Sharing was enabled on a Mac, an attacker on the same network could log in without valid credentials. The bug was tied to the screensharingd service, which reportedly mishandled Secure Remote Password, or SRP, authentication and returned an outdated success state, causing an unauthenticated connection to be treated as authenticated. The report said that meant an attacker needed neither a valid macOS account nor an old VNC password to log in as any user. A proof of concept published by security researchers went further, showing the issue could be used to read and write files, execute code remotely with root privileges, and establish persistence through LaunchDaemons or shell startup files. The vulnerability was reported by Alfredo Pesoli through Bynario Atlas. Apple said it has no evidence of active exploitation so far. For crypto users who store private keys, seed phrases, or software wallets on a Mac, the risk is acute because a compromised endpoint can expose wallet data regardless of local password protections. Apple has released fixes in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

If you use a Mac to manage crypto assets, this is an issue to deal with quickly. Apple patched a major macOS Screen Sharing authentication bug, CVE-2026-65400, on Aug. 6. According to Apple’s security advisory, if Screen Sharing was enabled, an attacker on the same network could log into the machine without valid credentials.

The flaw was tied to screensharingd

The report said the vulnerability sat in macOS’s screensharingd service. During Secure Remote Password, or SRP, authentication, the service allegedly used incorrect message-length validation and returned an outdated “success” state. That caused a connection that had not actually passed authentication to be treated as authenticated.

In practice, that meant an attacker on the network needed neither a valid macOS account nor a legacy VNC password to log in as any user.

PoC showed file access, remote code execution, and persistence

A proof of concept released by security researchers showed the bug could do more than bypass login. According to the report, it could be used to read and write files at will, execute programs remotely with root privileges, and maintain persistence through LaunchDaemons or shell startup files.

The vulnerability was reported by Alfredo Pesoli through Bynario Atlas. Apple said it currently has no evidence that the flaw has been exploited in real-world attacks, and a full technical write-up is expected later.

Why it matters for self-custody users

For users who keep private keys, seed phrases, or software wallets on a Mac, the impact is especially severe. Once an attacker can log into the computer and read or write files as root, local wallet passwords and encryption protections can effectively be bypassed.

The issue is not on-chain, but it can directly affect control of on-chain assets.

Available fixes

Apple has released patched versions in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Users on those versions can update their systems immediately.

If Screen Sharing is not part of your regular workflow, the report also advised turning it off through System Settings → General → Sharing to reduce exposure.

The report also noted that Chain News had previously covered another macOS kernel vulnerability, CVE-2026-28952. For self-custody users, endpoint security is often overlooked, but the consequences are immediate if the device itself is compromised.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
210

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.