PT-2026-68772 · Apple · Macos Tahoe+3
CVE-2026-65400
·
Published
2026-08-06
·
Updated
2026-09-01
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
macOS Tahoe versions prior to 26.6.1
macOS Sequoia versions prior to 15.7.9
macOS Sonoma versions prior to 14.8.9
Description
An authentication bypass exists in the built-in Screen Sharing feature, which allows remote desktop management via the VNC protocol on TCP port 5900. The issue stems from improper state management during the authentication process, allowing a network attacker to authenticate without valid credentials. This can lead to full system compromise with root privileges. Real-world exploitation has been observed on systems with port 5900 exposed to the internet, where attackers deployed Monero cryptocurrency miners. A list of approximately 24,000 potentially exposed hosts has been circulated by threat actors.
Recommendations
Update macOS Tahoe to version 26.6.1.
Update macOS Sequoia to version 15.7.9.
Update macOS Sonoma to version 14.8.9.
As a temporary workaround, disable the Screen Sharing feature in System Settings if it is not required.
Close TCP port 5900 to the internet and use a VPN or SSH tunneling for remote access.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Macos Sequoia
Macos Sonoma
Macos Tahoe