Apple has closed a flaw in the macOS screen sharing feature. Attackers on the network were able to log into other people's Macs without holding valid credentials. macOS 14 (Sonoma), macOS 15 (Sequoia) and macOS 26 (Tahoe) are affected. The fixed builds are 14.8.9, 15.7.9 and 26.6.1.
The bug is tracked as CVE-2026-65400. Security researcher Alfred Persoli found it using Bynario Atlas, an AI driven platform for vulnerability discovery. Apple is keeping the details thin. The company only states that an attacker on the network could authenticate to screen sharing without the correct credentials, and that the issue was resolved with improved state management. What that means in practice is anyone's guess.
Full control, not just a peek
Once someone reaches a Mac through screen sharing, they operate it like a person sitting in front of it. Keyboard, mouse, files, applications. macOS ships two flavours of the feature. Basic screen sharing is built into every Mac and covers both sharing and remote control. Administrators tend to use Apple Remote Desktop, which costs around 90 euros and adds management tooling on top.
The power settings make this worse than it sounds. Depending on how a machine is configured, it can be woken from sleep for a remote session. On a MacBook that works even with the lid closed, as long as the machine is plugged in.
The gaps Apple did not fill
Several questions remain open. Apple does not say whether screen sharing has to be switched on, or whether the attack also works when sharing is disabled. New Macs ship with it off. It is equally unclear whether an attacker really had to sit inside the local network. Where ports are forwarded for internet access, which happens in plenty of corporate setups, the picture may look different. Apple also said nothing about older macOS releases that no longer get updates. Assume they are exposed too.
Your move
Install the update, and do not sit on it. Then open System Settings, go to General and Sharing, and confirm that screen sharing and remote management are only enabled where you actually need them. If you administer Macs remotely, route that access through a VPN instead of forwarding ports on the router. It takes five minutes and removes the foundation for a whole category of network attacks.