
CVE-2026-65400
Apple macOS
•
severity
published
An authentication state-management flaw in macOS Screen Sharing can allow a remote attacker to establish a session without valid credentials. Bynario demonstrated that the resulting unauthorized session could be chained with privileged Screen Sharing file-copy behavior to achieve remote root command execution.
Exploitation requires Screen Sharing to be enabled.
Apple fixed the issue through improved state management in macOS Sonoma 14.8.9, macOS Sequoia 15.7.9, and macOS Tahoe 26.6.1. NVD classifies it as CWE-287.
References
Explore our other findings
