Apple has rushed out a uncommon single-fix macOS replace to deal with a Display Sharing flaw that might let attackers get previous authentication.
Apple launched macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9 on August 6, addressing the identical vulnerability throughout all three supported variations.
The flaw, tracked as CVE-2026-65400, impacts Screen Sharing and will permit an attacker on the community to authenticate with out legitimate credentials. Apple says it mounted the issue by way of “improved state administration,” in response to its security advisory.
Apple credit safety researcher Alfredo Pesoli, reporting by way of Bynario Atlas, with discovering the problem. The corporate has not mentioned that the vulnerability has been exploited within the wild.
Why the display screen sharing bug issues
Display Sharing is designed to let customers remotely view and management a Mac. That makes an authentication failure notably critical: If an attacker can set up a session with out legitimate credentials, the safety boundary defending distant entry can successfully break down.
Apple’s advisory doesn’t clarify how the flaw works or specify the community circumstances required for exploitation.
Safety researchers cited by Forbes describe the problem as doubtlessly extra extreme. Huntress principal safety operations middle analyst Ryan Dowd mentioned the vulnerability includes Display Sharing’s implementation of Safe Distant Password and “finally permits pre-authenticated distant code execution on all supported macOS variations.”
That evaluation goes past Apple’s temporary advisory, nonetheless, and the corporate has not publicly confirmed these technical particulars.
Why Apple moved rapidly
Apple typically bundles security fixes into scheduled software program releases, however this replace reveals the corporate was prepared to challenge a separate patch when a vulnerability affected a built-in distant entry characteristic.
The corporate additionally utilized the repair throughout three supported macOS variations as an alternative of limiting it to the most recent launch. That strategy offers customers who stay on Sequoia or Sonoma safety with out requiring a direct working system improve.
For customers, the replace is a reminder that even trusted built-in instruments can turn into safety entry factors when authentication methods fail. Remote access features are designed for comfort, however additionally they present attackers with helpful targets if protections break down.
What Mac customers ought to do
Mac customers operating Tahoe, Sequoia, or Sonoma ought to set up the most recent safety replace by way of System Settings > Basic > Software program Replace.
Customers who don’t want Display Sharing must also evaluate whether or not the characteristic is enabled below System Settings > Basic > Sharing and take into account turning it off when it’s pointless. Nonetheless, disabling Display Sharing shouldn’t change putting in the replace. A patched system protects you if the characteristic is required later or by chance enabled.
Additionally learn: Apple briefly removed Telegram from the App Retailer over a reported CSAM violation earlier than restoring the app later that day.