{
  "id": 18514,
  "title": "Apple Screen Sharing Pre-Auth RCE",
  "url": "https://urgent.news/2026/08/01/apple-screen-sharing-pre-auth-rce",
  "topic": "culture",
  "section": "Culture",
  "published": "2026-08-01T19:39:20.000Z",
  "source": {
    "name": "Lobsters",
    "slug": "lobsters",
    "url": "https://warez.sl0p.foo/apple-screensharing-rce/"
  },
  "original_language": "en",
  "account": "Apple's Screen Sharing daemon (screensharingd) has a pre-authentication vulnerability in its SRP frame-length validation process. This flaw allows an attacker to manipulate the frame length, bypassing authentication and gaining root-level access to the system. No user interaction or knowledge of the target's configuration is required for this exploit. The flaw occurs when screensharingd receives an SRP frame whose length exceeds 32,767 bytes, causing the daemon to interpret the error path's return value as authentication completion. This triggers the post-auth message loop, allowing the attacker to inject and execute arbitrary code, such as a reverse shell and root crontab, within 60 seconds. The exploit targets a Mac with Screen Sharing enabled, which is enabled by default on stock Macs. The vulnerability exists in the SRP validation process and is not affected by SIP (System Integrity Protection), a security feature that protects the system from unauthorized modifications. The exploit is independent of any password or valid username requirements and works on any Mac running macOS 26.3 with Screen Sharing enabled.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}