Critical macOS screen sharing flaw allows passwordless remote login; Apple fixes it in version 26.6.1

Critical macOS screen sharing flaw allows passwordless remote login; Apple fixes it in version 26.6.1

N
News Editor
2026-08-08 14:34:27
A critical security flaw in macOS screen sharing could let a network attacker log into a Mac with any account without knowing the password, according to a disclosure by security researcher Calif tracked by Dongcha Beating. The bug, assigned CVE-2026-65400, affects systems with screen sharing enabled and was described as a form of unauthenticated remote code execution that can give an attacker full desktop control. Calif said the root cause and exploitation method were identified after reverse-engineering Apple’s macOS 26.6.1 patch, and proof-of-concept code has already been released. Apple has fixed the issue in macOS 26.6.1 and users are advised to update as soon as possible. While there is no evidence so far of broad exploitation in real-world environments, the public release of PoC code is raising the risk for unpatched machines. For users who cannot update right away, turning off screen sharing is cited as a temporary mitigation until the patch can be installed.

Security researcher Calif has disclosed a critical flaw in macOS screen sharing, tracked as CVE-2026-65400.

According to monitoring cited by Dongcha Beating, if screen sharing is enabled on a user’s Mac, any network attacker could exploit the bug to log into the machine with any account without knowing the password. Calif said reverse-engineering of Apple’s macOS 26.6.1 patch identified both the root cause and the exploitation method, and proof-of-concept code has been released.

Patched in macOS 26.6.1

Apple has fixed the vulnerability in macOS 26.6.1, and Mac users are urged to update to that version as soon as possible. A full technical analysis is scheduled for release tomorrow.

The flaw was classified as Critical. The disclosure described it as unauthenticated remote code execution that could hand an attacker full desktop control, placing it among the most severe categories of desktop operating system vulnerabilities.

Risk rising for unpatched systems

There is currently no evidence that the issue has been widely exploited in real-world environments. Still, with proof-of-concept code now public, the risk to unpatched systems is rising quickly. For users who cannot update immediately, disabling screen sharing before upgrading is listed as a temporary mitigation.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
610

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.