Skip to content

MacPublished 5 min read

Exploited Screen Sharing bypass CVE-2026-65400, fixed in macOS Tahoe 26.6.1 (August 14, 2026)

Illustration for the article “Exploited Screen Sharing bypass CVE-2026-65400, fixed in macOS Tahoe 26.6.1 (August 14, 2026)”
Listen to this article · 8:13 · AI-generated narration
0:00 / 8:13
Chapters

What the flaw actually is

Screen Sharing on a Mac is served by screensharingd, which listens on TCP port 5900. Huntress described the defect on August 7, 2026 as a pre-authentication remote code execution flaw in the SRP implementation of Screen Sharing's native Apple authentication path. The daemon's frame-length validator "erroneously returns a stale success status, so the connection is treated as authenticated", and what follows is a cleartext session in which the attacker reads and writes files as root.

Apple's own wording is narrower. The security note for macOS Tahoe 26.6.1, published by Apple Support on August 6, 2026, lists a single entry: component Screen Sharing, impact "An attacker on the network may be able to authenticate to Screen Sharing without valid credentials", description "An authentication issue was addressed with improved state management." The credit reads CVE-2026-65400: Alfredo Pesoli via Bynario Atlas.

The important word is pre-authentication. The bypass happens before any credential is checked, so nothing you do to accounts or passwords on the Mac changes the outcome. Huntress reports the flaw as affecting builds up to August 5, 2026, with the August 6 updates carrying the fix.

TL;DR

Macs running macOS Tahoe 26.6 or earlier are being broken into through CVE-2026-65400, an authentication bypass in Screen Sharing, according to BleepingComputer on August 14, 2026. Apple had already shipped the fix on August 6, 2026 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Installing the update closes the door, but it does not evict an attacker who is already inside.

  • CVE-2026-65400 needs no account and no VNC password. Network reach to TCP port 5900 is the whole prerequisite.
  • The Dutch NCSC reported active abuse on multiple systems whose port 5900 was reachable from the internet.
  • In the confirmed cases the attackers took root and installed a Monero cryptocurrency miner.
  • The fix is macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 or macOS Sonoma 14.8.9, all released August 6, 2026.
  • Turning Screen Sharing off is the stopgap, and it costs you remote screen access completely.

What the attackers did after getting in

BleepingComputer quotes the Dutch national cyber security centre, NCSC-NL, saying that "active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet". In the confirmed cases the attackers "obtained root access to the system and deployed a Monero cryptocurrency miner".

Huntress gives the shape of the session in the logs: a session username of root, an authentication type of SRP, and no RSA encryption on the connection. A mining payload is not subtle either: it burns processor time, so on a Mac that had port 5900 open, an idle machine running hot and loud is worth a look.

Which versions carry the fix

Apple shipped these updates out of band, ten days after its scheduled July 27, 2026 releases. If your Mac was updated in July and not since, it is not patched for this.

There is a second, older Screen Sharing bug that is easy to confuse with this one. Huntress describes CVE-2026-43760 as a post-authentication confused-context condition that required legacy VNC authentication, and it was fixed by the July 27, 2026 updates: macOS Tahoe 26.6, macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8. Those builds are exactly the ones now exposed to CVE-2026-65400.

macOS lineVersion with the CVE-2026-65400 fixReleasedLast exposed version
macOS Tahoe26.6.1August 6, 202626.6
macOS Sequoia15.7.9August 6, 202615.7.8
macOS Sonoma14.8.9August 6, 202614.8.8

Why the usual hardening does nothing

Huntress is blunt about the mitigations people reach for first: individual Screen Sharing properties provide no protection. Removing allowed users from the Sharing pane, switching off legacy VNC password authentication and rotating the VNC password all leave the hole open, because the daemon decides the connection is authenticated before any of those settings are consulted. Huntress gives two options: patch now, or disable Screen Sharing.

Disabling it has a real cost. You lose built-in remote screen access and remote control on that Mac, which for a machine in another building or another city can mean a trip. It is still the right call until the update is on. Note also what an update does not do: it replaces system files, and it does not remove a launch daemon or an account an intruder added. A Mac that was reachable on port 5900 needs to be examined, not just updated.

What to do today

1. Open System Settings, go to General, then Software Update, and install macOS Tahoe 26.6.1, or macOS Sequoia 15.7.9 or macOS Sonoma 14.8.9 if you are on an older line. Restart when it asks.

2. If you cannot update right now, open System Settings, go to General, then Sharing, and switch off Screen Sharing and Remote Management on that same pane.

3. Block inbound TCP port 5900 at your router or firewall, and stop forwarding it from the internet.

4. If the Mac was reachable from the internet on port 5900 before August 6, 2026, treat it as compromised: look for launch daemons you did not install in /Library/LaunchDaemons, look for a process holding the processor at full load, and get the machine examined rather than assuming the update settled it.

5. Turn Screen Sharing back on only once the Mac is patched and the port is no longer exposed.

If you would rather not work through that list by hand, Get XLAnt.

Frequently asked questions

Does installing macOS Tahoe 26.6.1 remove a miner that is already running?

No. The update closes the authentication bypass. Anything an intruder left behind, such as a launch daemon or an added account, survives it, which is why an exposed Mac needs to be inspected.

Is turning off Screen Sharing enough on its own?

It removes the exposure while it is off, and Huntress names it as the fallback when you cannot patch immediately. It costs you all remote screen access, and it is not a substitute for the August 6, 2026 update.

All articles