Critical Security Flaw Discovered in macOS Screen Sharing

A high-severity security vulnerability, tracked as CVE-2026-65400, has been disclosed in macOS's Screen Sharing feature. Security researcher Calif found that when this feature is enabled on a Mac, remote attackers could exploit the flaw to log into the computer as any user without requiring a password, gaining full control of the desktop.

Understanding the Vulnerability and Its Impact

This is classified as an authentication-bypass remote code execution vulnerability. In practical terms, if your Mac has Screen Sharing turned on, an attacker could potentially access everything on your computer—files, applications, and data—from anywhere on the internet, with no credentials needed. It represents one of the most severe types of threats for a desktop operating system.

Through reverse-engineering the macOS 26.6.1 patch released by Apple, the researcher confirmed the root cause and exploitation method. Proof-of-concept code has been made public, which significantly increases the risk for unpatched systems. While there's no current evidence of widespread exploitation in the wild, the availability of this code raises the likelihood of future attacks.

Apple's Fix and Recommended User Actions

Apple has addressed this critical issue in the macOS 26.6.1 update. The company urges all Mac users to install this update without delay.

Immediate steps for users:

  • Primary Action: Update your macOS to version 26.6.1 or later immediately. Go to System Settings > General > Software Update.
  • Temporary Workaround: If you cannot update right away, disable Screen Sharing as a precaution. Navigate to System Settings > General > Sharing and turn off "Screen Sharing."
  • Ongoing Vigilance: Even after updating, make it a habit to install security updates promptly and enable remote access features only when necessary and from trusted sources.

A detailed technical analysis is expected to follow. This incident underscores a fundamental rule of cybersecurity: keeping your operating system updated is the first and most crucial defense against evolving threats.