macOS High-Risk Vulnerability Discovered: Remote Login Possible Without Password When Screen Sharing is Enabled, Update to Version 26.6.1 Recommended
According to ThreatWatch Beating monitoring, security researcher Calif disclosed a severe security vulnerability in the macOS screen sharing feature (CVE-2026-65400). If a user's computer has screen sharing enabled, any network attacker can exploit this vulnerability to log in to the computer with any account without needing to know the password. The researchers reverse-engineered the patch released by Apple for macOS 26.6.1, have identified the root cause of the vulnerability, outlined the exploitation method, and published a proof-of-concept code.
Apple has fixed this vulnerability in macOS version 26.6.1, and all Mac users should upgrade to this version as soon as possible. The full technical analysis report will be released tomorrow. The vulnerability has been classified as "Critical" — unauthenticated remote code execution means that an attacker can gain full desktop control, making it one of the most severe types of security vulnerabilities in desktop operating systems. Currently, there is no evidence to suggest widespread exploitation of this vulnerability in the wild, but given the public availability of the proof-of-concept code, unpatched systems are at rapidly increasing risk. If users are temporarily unable to upgrade, disabling the screen sharing feature before upgrading can serve as a temporary mitigation measure.
Click on the original text link below to join ThreatWatch Beating · Feishu AI News Channel, which monitors global AI hot topics and news 24/7.