ON
← Back to feed
Screen Sharing in macOS: A vulnerability that allows access without authentication
Germany🏛️ PoliticsCenter17 days ago

Screen Sharing in macOS: A vulnerability that allows access without authentication

Ein Sicherheitsproblem in der Screen-Sharing-Funktion von macOS ermöglichte es Angreifern, Mac-Geräte im lokalen Netzwerk ohne Authentifizierung fernzusteuren. Apple veröffentlichte Updates (14.8.9, 15.7.9, 26.6.1) zur Behebung des Fehlers, der unter der CVE-ID 2026-65400 bekannt ist. Der Fehler wurde durch Sicherheitsforscher Alfred Persoli entdeckt, wobei Apple keine detaillierten Informationen zum Problem bereitstellt. Die Vulnerabilität könnte potenziell genutzt werden, wenn Geräte im öffentlichen Netzwerk zugänglich sind. Benutzer werden dringend gebeten, ihre Systeme zu aktualisieren, da der Bug in mehreren macOS-Versionen besteht. Es ist noch unklar, ob ältere Versionen ebenfalls betroffen sind.

A critical security flaw in macOS's screen-sharing feature has been patched after allowing attackers to remotely control Mac computers without authentication. The vulnerability was discovered in at least three versions of macOS, 14 (Sonoma), 15 (Sequoia), and 26 (Tahoe), and was addressed by Apple late Thursday evening. The updated versions are now macOS 14.8.9, 15.7.9, and 26.6.1. The bug, identified under the CVE ID 2026-65400, was found by security researcher Alfred Persoli using Bynario Atlas, a system designed to detect software vulnerabilities through artificial intelligence. The flaw allowed unauthorized users within a local network to access and take control of other Mac devices without needing login credentials. According to Apple’s statement, an attacker could log into the screen-sharing function on affected systems without providing valid authentication. This means that anyone with physical or network access to the device could potentially gain remote control over another Mac, effectively acting as a local user. macOS offers several methods for screen sharing, including basic features available on all Macs and more advanced tools such as Apple Remote Desktop, which costs 90 euros. These tools allow administrators to manage multiple machines efficiently. However, screen-sharing functionality is typically limited to local networks unless specific ports are opened on a router. It remains unclear whether the discovered vulnerability can be exploited beyond this scope, particularly in environments where external internet access is configured, or if the attacker must physically be present on the same network. Apple did not specify whether the screen-sharing feature or Apple Remote Desktop must be active for an attack to occur, nor whether an attack is possible even if screen sharing is disabled by default. On new Macs, screen sharing is usually turned off by default. If enabled, however, an attacker could fully control the device from afar, making such a breach highly dangerous. Additionally, depending on settings, an attacker might be able to wake up a sleeping Mac, even one that is closed and connected to power, to perform remote operations. The fix involves improvements to the “state management” system, though the exact nature of these changes remains undisclosed. Users are strongly advised to update their systems immediately to mitigate potential risks. While it is not clear whether older macOS versions that Apple no longer supports are also vulnerable, it is likely that they could be affected. The company has not commented on this possibility, leaving users to assume that outdated systems may still pose a risk. Security experts emphasize the importance of keeping operating systems up to date, especially when critical flaws are discovered. As the digital landscape continues to evolve, ensuring robust security measures becomes increasingly vital. With the recent patch, Apple has taken a step toward addressing the issue, but vigilance among users remains essential to protect against emerging threats.

Go to the primary sources (5)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 7817 days ago
Screen Sharing in macOS: A vulnerability that allows access without authentication

Ein Sicherheitsproblem in der Screen-Sharing-Funktion von macOS ermöglichte es Angreifern, Mac-Geräte im lokalen Netzwerk ohne Authentifizierung fernzusteuren. Apple veröffentlichte Updates (14.8.9, 15.7.9, 26.6.1) zur Behebung des Fehlers, der unter der CVE-ID 2026-65400 bekannt ist. Der Fehler wurde durch Sicherheitsforscher Alfred Persoli entdeckt, wobei Apple keine detaillierten Informationen zum Problem bereitstellt. Die Vulnerabilität könnte potenziell genutzt werden, wenn Geräte im öffentlichen Netzwerk zugänglich sind. Benutzer werden dringend gebeten, ihre Systeme zu aktualisieren, da der Bug in mehreren macOS-Versionen besteht. Es ist noch unklar, ob ältere Versionen ebenfalls betroffen sind.

Bias read (Center): Der Artikel berichtet objektiv über eine technische Sicherheitslücke in macOS, ohne politische Einflussnahme oder parteiliche Haltung zu zeigen. Er präsentiert Fakten, Quellen und Empfehlungen neutral, ohne eine bestimmte politische Richtung zu favorisieren.

Why factuality (85): The article accurately reports the existence of a vulnerability in macOS Screen Sharing that allows unauthorized access without credentials, referencing the CVE-ID 2026-65400 and attributing the discovery to Alfredo Pesoli via Bynario Atlas. It mentions the affected versions (14, 15, 26) and the pat

Why objectivity (78): The tone remains generally neutral, but there is some subtle emphasis on the severity of the vulnerability ('Lücke ermöglichte Zugriff ohne Authentifizierung') and a call to 'dringend aktualisieren', which implies urgency. While not overtly biased, this phrasing leans slightly towards highlighting t

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories