Skip to main content Skip to local navigation

macOS Screen Sharing Authentication Bypass (CVE-2026-65400)

 

A picture containing text  Description automatically generated

 

Information Security Advisory

 

A recently disclosed vulnerability (CVE-2026-65400) affects Apple macOS Screen Sharing and may allow a remote attacker on the network to authenticate without valid credentials, potentially gaining unauthorized access to affected systems.

Severity level:
CVSS Score: 9.8/Critical.

Description:

CVE-2026-65400 is a critical authentication bypass vulnerability in the macOS Screen Sharing component. Due to improper state management during authentication, a network-based attacker may be able to establish a Screen Sharing session without valid credentials. Successful exploitation could allow unauthorized access to affected macOS systems and remote control of exposed devices.

Affected Versions:

  • macOS Sonoma versions prior to 14.8.9.
  • macOS Sequoia versions prior to 15.7.9.
  • macOS Tahoe versions prior to 26.6.1.

                                            
Impact:
Successful exploitation may allow attackers to gain unauthorized remote access to affected macOS systems.

Resolution:
Upgrade affected systems to:

  • macOS Sonoma version 14.8.9 or later.
  • macOS Sequoia version 15.7.9 or later.
  • macOS Tahoe version 26.6.1 or later.

 

Mitigations:

  • Disable Screen Sharing on systems where it is not required.
  • Limit Screen Sharing access to trusted IP addresses and administrative networks.
  • Monitor systems for unauthorized remote access attempts and unusual account activity.
  • Review internet-facing macOS systems to ensure Screen Sharing is not unnecessarily exposed.


Reference:

https://nvd.nist.gov/vuln/detail/cve-2026-65400

https://www.cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-823

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400

https://www.tenable.com/cve/CVE-2026-65400

 

 

UIT Information Security




Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web