Загрузка видео...
Не удалось загрузить видео
PoC for a critical vulnerability in Apple macOS Screen Sharing (CVE-2026-65400). If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password. We reverse engineered Apple’s unusual macOS 26.6.1 patch to understand the root cause and exploitation path.... show more
455,242 просмотров • 1 месяц назад •via X (Twitter)
Комментарии: 27

the login screen becoming optional is a new level of screen sharing

Always use Screen Sharing behind VPN

Any idea how far back this goes?

How much for the bounty?

is the blog article out ?

The classic most secure ecosystem in the world moment.

I knew this exploit must have been really bad for apple to push out a patch so quickly for macOS Tahoe!!

Unless you deployed SentinelOne…. Which then thinks the update is malware. So that’s fun.

Screen sharing/remote access exposure is something we flag constantly during TSCM and corporate security sweeps. This kind of reverse-engineering writeup is a great reminder to keep those services locked down. Thanks for sharing.

@geerlingguy I know you use this feature😬

I think they leave these things on purpose

that's not a bug but a feature :v

really curious what the patch diff reveals here. did apple repair the authentication flow itself, or just block this path?

31337 FTW

I got a bunch of Intel Macs and pray daily that I don't need to update to Tahoe. I even still got transparency in Terminals! Time to check if screen sharing's off...

Which is the severity?

Yikes

@grok how much apple paid for this bug😅

@thegrugq Yuge

Never trusted any of the "sharing" options in the sharing panel - I was right, I guess

Yo 😳

This is why I disable Screen Sharing. But does the patch fully close the hole or just make it harder?

Truly Sharing with anyone that wants it...

the patch is the easy part. screen sharing gets turned on once by remote management and then stays on for years, so the install base that matters is the machines nobody remembers enabling it on. keeping it off a flat network is what actually shrinks the pre auth surface.

Now that should be fun.

What's this pls

Reminder for folks to use tailscale / wireguard to connect between your devices. Also enable the in-built apple firewall and restrict incoming conections.
