Sceawere

Vulnerability Detail

CVE-2026-65400UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Screen Sharing Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
1d ago
Vendor
Apple
Product
macOS
Attack Type
An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-06T22:18:14.533Z",
  "pubdate": "2026-08-06T22:18:14.533Z",
  "executiveSummary": "An authentication bypass vulnerability has been identified within the Screen Sharing component across multiple Apple operating system versions, specifically affecting macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. The root cause stems from improper state management within the authentication subsystem, which fails to adequately validate session states during connection establishment. This flaw allows an unauthenticated remote attacker positioned on the network to successfully authenticate to the Screen Sharing service without providing valid credentials.\nThe primary impact of this vulnerability involves unauthorized remote access to affected host systems, potentially exposing sensitive user interfaces, data, and system resources to malicious actors. Because the attack vector relies on network positioning, an adversary with local network access can bypass standard authentication mechanisms entirely, negating the security controls intended to protect remote management interfaces.\nRisk implications are critical, as successful exploitation grants unauthorized administrative or interactive visibility into the target machine. Remediation requires applying the official software updates provided by the vendor for the specified affected versions. No complex exploitation requirements are noted beyond network proximity to the vulnerable service, emphasizing the urgency of applying the addressed updates.",
  "technicalDetails": "The vulnerability resides within the Screen Sharing application component responsible for handling client authentication and session state transitions. Specifically, the flaw is caused by insufficient state management logic during the handshake and credential verification phases of the remote connection protocol. When a client initiates a connection to the Screen Sharing daemon, the application fails to rigorously verify whether the session state transitions correspond to a successfully authenticated user context.\nBecause of this state management flaw, an attacker on the network can manipulate or bypass the sequence of authentication checks by sending crafted connection initiation and state transition sequences. The vulnerable component incorrectly treats unauthenticated or partially initialized sessions as validly authenticated states, granting the remote entity access to the Screen Sharing session without requiring the submission of a valid username, password, or cryptographic token.\nThe attack flow proceeds as follows: First, the attacker scans the local network to identify systems exposing the Screen Sharing service. Second, the attacker establishes a network connection to the target service port. Third, by exploiting the flawed state management logic, the attacker injects or manipulates state variables within the communication stream, causing the service to falsely register the connection as authenticated. Finally, the service provisions the remote desktop interface to the attacker, allowing interactive access without credential validation.\nAffected products and versions include macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1. Privilege requirements for the attacker are minimal regarding local system access, though the attacker must be positioned on the network to reach the vulnerable Screen Sharing service. No prior privileges on the target host are required. Post-exploitation impact includes full visual access to the desktop, potential manipulation of host resources depending on active user sessions, and increased exposure to secondary attacks leveraging the established interactive session."
}
CVE-2026-65400: Screen Sharing Authentication Bypass Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere