Impact
An authentication flaw in macOS Screen Sharing allows an attacker with network access to authenticate without valid credentials, enabling unauthorized remote control or data disclosure. The issue stems from improper state management that fails to verify credentials before establishing a remote session, a violation of authentication controls identified as CWE‑287. This flaw effectively bypasses authentication on the remote desktop service.
Affected Systems
Apple macOS versions prior to Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 are affected. The vulnerability exists in any release before these update levels and can be mitigated by upgrading to the specified patch versions.
Risk and Exploitability
The vulnerability can be exploited from any network position that reaches the target machine’s Screen Sharing port. The EPSS score is 10%, but the CVSS score is 9.8, indicating high severity. The vulnerability is listed in the CISA KEV catalog, but it presents a clear threat to affected systems until patched. Attackers require only that the remote desktop service be reachable; no privileged escalation beyond the service is required.
OpenCVE Enrichment