Apple has revealed what today’s macOS security updates actually fix, confirming that macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 all address the same Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials.
The company initially released all three updates with only a brief note about important security fixes, but it has now published full security details explaining the issue and why users should install the updates.
Don’t miss the best of The Mac Observer
Set us as a preferred source and our Apple reporting ranks higher in your Google Search results and Discover feed — one tap, no account changes.
Apple says the flaw affected Screen Sharing across all three supported macOS versions and fixed the problem by improving how authentication states are managed.
Although the company has not reported any evidence that attackers actively exploited the vulnerability, the nature of the bug means it had the potential to give unauthorized users remote access to a vulnerable Mac if the necessary conditions were met.
Apple explains the Screen Sharing security fix
Apple published the following security advisory for all three macOS versions:
Screen Sharing
Impact: “An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.”
Description: “An authentication issue was addressed with improved state management.”
CVE-2026-65400, reported by Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io).
According to Apple’s advisory, the vulnerability allowed an attacker on the same network to bypass Screen Sharing authentication under certain conditions.
If successful, that access could let someone view the display, open apps and files, or perform other actions depending on how the affected Mac was configured and what permissions were available during the session.
Apple has not said that anyone used this vulnerability in real world attacks, but releasing fixes for macOS Tahoe, Sequoia, and Sonoma at the same time shows that the company considered the issue important enough to patch immediately instead of waiting for a larger software update. If your Mac supports one of these versions, installing the latest security update helps protect your system from this authentication flaw.
Discussion