Apple macOS

severity

8.0

published

When legacy VNC-password access is enabled for macOS Screen Sharing, its file-copy helpers can retain root filesystem privileges after authentication. An attacker who knows the configured VNC password can remotely create root-owned files; Bynario used this primitive to install a valid sudoers policy and obtain a root shell, demonstrating post-authentication remote root command execution.

Bynario identified the flaw in both directions of the Screen Sharing file-copy protocol. The sender helper could read an attacker-selected protected path with root filesystem credentials and return its contents to the viewer. The receiver helper could create attacker-controlled files with root credentials. Both paths resulted from failing to bind file-copy helper privileges to the authenticated macOS user.


References

CVSS v3.1

8.0

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS v3.1

8.0

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS v3.1

8.0

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

S&t5aIr6t4  lQoEoJkBiHn9g9  a8tE  y@o1uIrP  sZoFfYt3w@aLrBeR  c7r3iNt&iNc2aAl&lHyB.I

request briefing

request briefing

SVtPaPr8t#  lOoXo%kJiMn$gC  aRtQ  yBoXu6r$  sXoXfWt9wJaTr2eE  cZr$iWt1iJc9aGlClIyP.E

request briefing

request briefing

S2t9aQrGt&  lWoYo5k@i4n8gP  a%t6  ySo&u1rR  sToXf$t@wKaTrJe$  cZr4iKtKiQc7aQlBl8y#.3

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026