Description
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Apple / macOS0 – 14.8.9
- Apple / macOS0 – 15.7.9
- Apple / macOS0 – 26.6.1
- Apple / macOS14.0 – 14.8.9
- Apple / macOS0 – 26.7
- Apple / macOS0 – 27
News coverage
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe Hacker News · 8/19/2026
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero MinerThe Hacker News · 8/15/2026
References
- VENDOR_ADVISORYhttps://support.apple.com/en-us/148170
- VENDOR_ADVISORYhttps://support.apple.com/en-us/148171
- VENDOR_ADVISORYhttps://support.apple.com/en-us/148172
- VENDOR_ADVISORYhttps://support.apple.com/en-us/149035
- VENDOR_ADVISORYhttps://support.apple.com/en-us/149042
Updated 9m ago · 8 sources