Description
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.
Published: 2026-07-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local attacker may determine the legacy VNC password configured for Screen Sharing because the system lacked the necessary entitlement checks during the authentication process. This flaw permits the disclosure of credentials that were intended to be protected, potentially exposing the password to anyone with local access to the machine.

Affected Systems

Apple macOS devices running earlier than macOS Sequoia 15.7.8 or macOS Sonoma 14.8.8 are affected. The vulnerability applies to any release of these macOS families prior to the specified fix updates.

Risk and Exploitability

The CVSS score of 5.5 signals a medium severity vulnerability, and the EPSS score of <1% indicates a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Because the flaw is local, an attacker needs local access or privileges to read the legacy VNC password; there is no known public exploit beyond this local disclosure scenario.

Generated by OpenCVE AI on August 4, 2026 at 13:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update macOS to at least macOS Sequoia 15.7.8 or macOS Sonoma 14.8.8, which enforce proper entitlement checks.
  • Disable VNC/Screen Sharing if not required for legitimate remote management.
  • Restrict local user accounts and enforce strict access controls to reduce the risk of local privilege escalation.
  • Monitor system logs for attempts to read legacy VNC passwords or unusual VNC access patterns.

Generated by OpenCVE AI on August 4, 2026 at 13:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Disclosure of Legacy VNC Password via Missing Entitlement Checks on macOS

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local VNC Password Disclosure via Screen Sharing Entitlement Check Bypass
Weaknesses CWE-200
CWE-285

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local VNC Password Disclosure via Screen Sharing Entitlement Check Bypass
Weaknesses CWE-200
CWE-285
CWE-862
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-07-28T15:05:24.738Z

Reserved: 2026-05-01T22:46:21.640Z

Link: CVE-2026-43665

cve-icon Vulnrichment

Updated: 2026-07-28T15:05:20.395Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T21:16:52.457

Modified: 2026-07-29T17:02:48.330

Link: CVE-2026-43665

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses