macOS screen sharing flaw let attackers log into Macs without a password on the same network
Apple patched a serious macOS screen sharing authentication flaw, tracked as CVE-2026-65400, on Aug. 6. According to Apple’s security advisory, if Screen Sharing was enabled on a Mac, an attacker on the same network could log in without valid credentials. The bug was tied to the screensharingd service, which reportedly mishandled Secure Remote Password, or SRP, authentication and returned an outdated success state, causing an unauthenticated connection to be treated as authenticated. The report said that meant an attacker needed neither a valid macOS account nor an old VNC password to log in as any user. A proof of concept published by security researchers went further, showing the issue could be used to read and write files, execute code remotely with root privileges, and establish persistence through LaunchDaemons or shell startup files. The vulnerability was reported by Alfredo Pesoli through Bynario Atlas. Apple said it has no evidence of active exploitation so far. For crypto users who store private keys, seed phrases, or software wallets on a Mac, the risk is acute because a compromised endpoint can expose wallet data regardless of local password protections. Apple has released fixes in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.








