Summary
CVE-2026-65400 is an authentication vulnerability in macOS Screen Sharing that may allow an attacker on the network to authenticate without valid credentials. The issue is caused by a flaw in authentication state management and can result in unauthorized access to the Screen Sharing service. Apple fixed the vulnerability in macOS Sonoma 14.8.9, Sequoia 15.7.9, and Tahoe 26.6.1.
Urgent Actions Required
- Update affected Macs to macOS Sonoma 14.8.9, Sequoia 15.7.9, or Tahoe 26.6.1.
- Disable Screen Sharing if it is not required.
- Restrict network access to Screen Sharing and avoid exposing port 5900 to the entire internet.
- Check potentially affected systems for signs of compromise, particularly where Screen Sharing was exposed to untrusted networks.
Which Systems Are Vulnerable to CVE-2026-65400?
Technical Overview
- Vulnerability Type: Improper Authentication (CWE-287)
- Affected Software/Versions:
- macOS Sonoma: versions earlier than 14.8.9
- macOS Sequoia: versions earlier than 15.7.9
- macOS Tahoe: versions earlier than 26.6.1
- CVSS Vector: v3.1
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: Low
- Availability Impact: None
- Patch Availability: Yes, available
How Does the CVE-2026-65400 Exploit Work?
The attack typically follows these steps:
What Causes CVE-2026-65400?
Vulnerability Root Cause:
CVE-2026-65400 results from an authentication flaw in the macOS Screen Sharing service. The issue is linked to improper state management during authentication, which can allow an attacker on the network to authenticate without valid Screen Sharing credentials. Apple addressed the flaw by improving the service’s state management.
How Can You Mitigate CVE-2026-65400?
If immediate patching is delayed or not possible:
- Disable Screen Sharing if it is not required.
- Restrict access to Screen Sharing through a firewall.
- Block inbound access to port 5900 from untrusted networks or the public internet.
- Check affected Macs for signs of compromise, especially if Screen Sharing was internet-accessible.
- Update macOS to the appropriate fixed version as soon as possible.
Which Assets and Systems Are at Risk?
- Asset Types Affected:
- Mac systems running vulnerable versions of macOS Sonoma, Sequoia, or Tahoe.
- Screen Sharing services enabled on affected Macs.
- Internet-accessible Macs where Screen Sharing can be reached from an untrusted network.
- Exposure Level:
- Internet-facing Macs with Screen Sharing accessible through port 5900.
- Macs on reachable networks where an attacker can access the Screen Sharing service.
- Unpatched systems running versions earlier than Sonoma 14.8.9, Sequoia 15.7.9, or Tahoe 26.6.1.
How Can You Detect CVE-2026-65400 Exploitation?
Exploitation Signatures:
- Screen Sharing authentication without valid credentials.
- Network access to Screen Sharing on an affected Mac.
Behavioral Indicators:
- Unauthorized Screen Sharing authentication without valid credentials.
- Cryptocurrency-mining activity on the affected Mac.
Alerting Strategy:
- Priority: Medium
- Priority: High
- Monitor for the listed Screen Sharing access and compromise indicators.
Remediation & Response
- Remediation Timeline:
- Immediate: Update affected Macs to Sonoma 14.8.9, Sequoia 15.7.9, or Tahoe 26.6.1.
- Until patched: Disable Screen Sharing or restrict port 5900 with a firewall.
- Incident Response Considerations:
- Check for compromise before and after updating, especially on Macs with exposed Screen Sharing.
- Back up important files to a remote computer if compromise is suspected.
- Reinstall macOS rather than relying on in-place malware removal after a confirmed compromise.
- Rotate credentials, SSH keys, and secrets stored on or used to access the affected Mac.
Uncover the Hidden Threats in Your Network Metadata
-
-
- NetFlow and packet capture limitations
- The value of rich, historical metadata
- Four secrets your metadata reveals
- Real-world threat detection insights
-
CVSS Breakdown Table
| Metric | Value | Description |
|---|---|---|
| Base Score | 7.1 | Reflects the risk of unauthorized Screen Sharing access on vulnerable Macs |
| Attack Vector | Network | The vulnerable Screen Sharing service can be reached by an attacker over the network |
| Attack Complexity | Low | The attack does not depend on unusual or difficult-to-reproduce conditions |
| Privileges Required | Low | The CVSS assessment assigns a low privilege requirement to exploitation |
| User Interaction | None | The victim does not need to perform an action for the vulnerability to be exploited |
| Scope | Unchanged | The impact remains within the security authority of the affected Screen Sharing service |
| Confidentiality Impact | High | Unauthorized Screen Sharing access may expose information on the affected Mac |
| Integrity Impact | Low | Unauthorized access may provide limited ability to affect information available through the service |
| Availability Impact | None | Exploitation is not expected to disrupt the availability of the affected system or Screen Sharing service |
References: