Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple’s latest macOS updates address a serious Screen Sharing vulnerability

Apple has now published the security details for today’s macOS Tahoe, Sequoia, and Sonoma updates , revealing that all three address a serious Screen Sharing vulnerability. Here is what Apple fixed.

Apple’s latest macOS updates address a serious Screen Sharing vulnerability

Apple has recently released security updates for macOS Tahoe, Sequoia, and Sonoma, addressing a significant Screen Sharing vulnerability. All three versions of the operating system received patches for the issue, described as a bug that would enable an attacker on a network to gain unauthorized access to a user's Screen Sharing session without the need for valid credentials.

The vulnerability, identified as CVE-2026-65400, was reported by Alfredo Pesoli (@__rev) via Bynario Atlas (bynar.io). Although there is no evident exploitation in the wild, Apple's description of the issue implies that an attacker could exploit the Screen Sharing authentication checks, potentially allowing them to remotely access a vulnerable Mac.

Depending on the system's configuration and privileges granted during the session, this could lead to the attacker viewing the screen, opening applications and files, or performing other actions on the Mac.

Apple has deemed the vulnerability as serious enough to patch across all three versions of macOS, even without prior beta testing or waiting for the next major round of OS updates. Users are advised to install the updates as soon as possible to mitigate the risk of exploitation. For more information about Apple's security updates, visit their security updates page.

Written by urgent.news from 9to5Mac's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 2 other outlets

Read the original at 9to5mac.com →

More in Tech

datasette 1.0a38

Release: datasette 1.0a38 This release fixes a SQL injection security issue that affects Datasette instances that serve a mixture of public and private tables in the same database, with access…

More from Thursday 6 August →