Technology

Apple Patches macOS Authentication Vulnerability That Allowed Remote Screen Hijacks

Updates for Sonoma, Sequoia, and Tahoe resolve an unauthenticated local network access flaw covering nine years of Mac hardware.

Apple has dispatched urgent security updates spanning three generations of macOS to close a critical vulnerability in its screen sharing architecture. The software patches address the vulnerability not only on the current flagship release, Tahoe, but also on preceding operating system builds.

Specifically, the Cupertino tech giant issued updates for macOS 14.8.9 (Sonoma), macOS 15.7.9 (Sequoia), and macOS 26.6.1 (Tahoe) to resolve a flaw that allowed remote actors to hijack the Mac Screen Sharing utility without supplying valid authentication credentials.

Tracked under the official designation CVE-2026-65400, the security gap has been neutralized through these latest system updates. Apple rolled out the fixes yesterday, making them immediately accessible for system installation.

While Apple refrained from releasing extensive technical details regarding the defect, the company confirmed the root cause stemmed from an underlying issue within the macOS authentication mechanism. The flaw enabled a malicious actor operating on the same local network to gain unauthorized entry to the Screen Sharing service without valid login credentials.

In practice, the macOS vulnerability could allow unauthorized individuals to observe a computer screen without user permission. Beyond passive monitoring, adversaries could potentially execute software applications, inspect sensitive files, or assume administrative control over other system components, depending on the session permission parameters.

Security analysts note that local network authentication bypasses pose significant threats in shared environments, such as enterprise offices or public Wi-Fi networks. Because macOS Screen Sharing builds on network remote desktop frameworks, a compromised authentication handshake allows attackers to bypass standard password barriers, putting unpatched systems on shared connections at immediate risk of silent takeover.

The Screen Sharing security flaw impacts a wide catalog of Apple hardware. Because the patches extend to legacy systems running macOS Sonoma, the underlying security vulnerability spans devices released across a nine-year hardware window.

Given that macOS 14 maintains backward compatibility with hardware as old as the 2017 iMac Pro alongside 2018 models of the Mac mini, MacBook Air, and MacBook Pro, owners operating these legacy systems or subsequent hardware iterations are advised to apply the updates.

The deployment fits an established pattern for Apple, which frequently remediates severe security vulnerabilities on discontinued hardware platforms and older operating system branches. Cupertino maintains active vulnerability monitoring across macOS, iOS, and iPadOS, allowing engineering teams to address critical threats regardless of device age or active software generation.

Over recent years, Apple has regularly published security updates for older iPhone and iPad models that no longer receive new user features, keeping legacy hardware protected against severe security risks. That same long-term maintenance approach is now being applied across the Mac lineup.

Users are instructed to deploy the newest updates for macOS Sonoma, Sequoia, and Tahoe to neutralize potential access vectors. Notably, Apple has not disclosed whether threat actors have actively exploited this Screen Sharing flaw in wild attacks prior to the patch release.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button