Impact
An authentication bypass exists in macOS Screen Sharing due to improper state management during session initiation. The flaw, identified as CWE‑287, allows an unauthenticated attacker to log in without valid credentials and obtain full remote control of the target machine. This can lead to unauthorized data access, system compromise, or further lateral movement within the network.
Affected Systems
Apple macOS releases before macOS Golden Gate 27, Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1, and Tahoe 26.7 are affected by this vulnerability. Any system running a version older than those specified is vulnerable until the vendor provides the corresponding fix.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, and the EPSS score of 1% indicates a low but nonzero probability of exploitation. It is listed in the CISA KEV catalog. The likely attack vector is a remote network connection to the device’s Screen Sharing service, commonly via TCP 5900. Based on the description, it is inferred that an attacker only needs access to the target’s network and the Screen Sharing port; no privilege escalation beyond what the service grants is required.
OpenCVE Enrichment