
CVE-2026-43760
Apple macOS
•
severity
published
When legacy VNC-password access is enabled for macOS Screen Sharing, its file-copy helpers can retain root filesystem privileges after authentication. An attacker who knows the configured VNC password can remotely create root-owned files; Bynario used this primitive to install a valid sudoers policy and obtain a root shell, demonstrating post-authentication remote root command execution.
Bynario identified the flaw in both directions of the Screen Sharing file-copy protocol. The sender helper could read an attacker-selected protected path with root filesystem credentials and return its contents to the viewer. The receiver helper could create attacker-controlled files with root credentials. Both paths resulted from failing to bind file-copy helper privileges to the authenticated macOS user.
References
Explore our other findings
