Apple macOS

•

severity

8.0

published

When legacy VNC-password access is enabled for macOS Screen Sharing, its file-copy helpers can retain root filesystem privileges after authentication. An attacker who knows the configured VNC password can remotely create root-owned files; Bynario used this primitive to install a valid sudoers policy and obtain a root shell, demonstrating post-authentication remote root command execution.

Bynario identified the flaw in both directions of the Screen Sharing file-copy protocol. The sender helper could read an attacker-selected protected path with root filesystem credentials and return its contents to the viewer. The receiver helper could create attacker-controlled files with root credentials. Both paths resulted from failing to bind file-copy helper privileges to the authenticated macOS user.


References

CVSS v3.1

8.0

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS v3.1

8.0

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS v3.1

8.0

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

SLtTaWrHt4  lNoCoQk1i@nZg#  aUtU  yLo0uErZ  s0oYf&tZwHa%rTe9  cDrYiBt4iAcMaFlFlOyZ.U

request briefing

request briefing

SRtKaJrVt$  l&oRo7kPiWnVgS  a&tE  y9oTuZrD  s&oVf$t%wMa@r9eV  c$r4iPtDiXcOa1lClSy7.0

request briefing

request briefing

SNt#aVrBt2  lPo6oBk9iYnNgN  a0tI  yOoNuJrJ  sFo3f0tRwAaXrUeU  cNrPi&tLiNc$a1lWlZy5.H

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026