Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Apple patches critical macOS flaw allowing passwordless root access via Screen Sharing

A severe authentication vulnerability in macOS, tracked as CVE-2026-65400, could let remote attackers gain root access without credentials when Screen Sharing is enabled. Apple has released patches for Sequoia, Sonoma, and Tahoe after evidence of active exploitation.

Featured image for Apple patches critical macOS flaw allowing passwordless root access via Screen Sharing
Featured image for Apple patches critical macOS flaw allowing passwordless root access via Screen Sharing

Apple has fixed a critical macOS vulnerability that could allow an attacker to remotely gain root access on a Mac simply by exploiting the built-in Screen Sharing feature, according to TechSpot.

The flaw, tracked as CVE-2026-65400, received a CVSS severity score of 9.8 out of a maximum of 10. The Netherlands' National Cyber Security Centre (NCSC-NL) issued an advisory describing the issue as an authentication problem caused by insufficient state management. In practical terms, an attacker could exploit this bug to break into a Mac over the network without providing any valid login credentials. Normally, the operating system would reject such an unauthorized login attempt, but the flaw bypasses that protection.

Apple has released separate patches for three affected macOS versions: Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The vulnerability affects all three desktop operating system lines.

According to TechSpot, the flaw was first discovered earlier this month. A week later, the NCSC-NL obtained evidence that a working proof-of-concept (PoC) exploit was spreading on the public internet. Unknown criminals have been using that PoC to compromise "multiple" Mac systems through port 5900, which is open when Screen Sharing is enabled. The attackers reportedly gained root access and then installed a Monero cryptomining trojan on vulnerable machines.

Root access is particularly dangerous because it disables native macOS security protections and makes it possible to plant virtually any kind of malicious code on the compromised system, TechSpot notes.

Apple credited Alfredo Pesoli, co-founder and CEO of the cybersecurity firm Bynario, with discovering the vulnerability. In a LinkedIn post, Pesoli said Bynario's automated, AI-assisted "Atlas" solution can help customers find and validate bugs of this severity.

TechSpot's reporting underscores that while zero-day vulnerabilities are often associated with Windows, macOS is not immune. This case also highlights the risk of leaving remote management features such as Screen Sharing exposed to untrusted networks.

Users are advised to apply the macOS updates immediately and disable Screen Sharing if it is not needed.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Cybersecurity

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'