macOS Screen Sharing Flaw Now Under Active Attack

A vulnerability Apple fixed in macOS Tahoe 26.6.1 is already being used by attackers to gain remote access to Macs.

The Vulnerability

Attackers have started exploiting a flaw in macOS Screen Sharing that bypasses authentication checks. The issue lets an unauthenticated remote party connect, view the screen, and control the keyboard and mouse. Once inside, the attacker can open files, run applications, and carry out any action available to the logged-in user.

Apple shipped the fix in macOS Tahoe 26.6.1 on August 6. The update arrived a little over a week after the release of macOS Tahoe 26.6. In its security support document, Apple described the problem as an authentication flaw in the Screen Sharing service that allowed connection without valid credentials.

The Netherlands' National Cyber Security Center observed the flaw in active use and notified Dutch organizations. No further technical details on the attack methods have been released by either the center or Apple.

How Screen Sharing Works on macOS

Screen Sharing is a built-in macOS service that lets one Mac display and control another over the network. It is commonly enabled for remote support, family assistance, or collaboration between machines on the same local network or across the internet. When left on by default or for occasional use, the service listens for incoming connections.

Before the patch, any Mac with the service enabled could be reached by an attacker who knew the machine's address. The bypass removed the need for a username and password that would normally gate access. This turned an optional remote-control feature into an open entry point.

The affected versions are those running macOS Tahoe 26.6 or earlier. Users must install 26.6.1 through the standard Software Update panel to close the hole. No workaround other than disabling Screen Sharing entirely has been documented.

Exploitation Confirmed

The National Cyber Security Center stated that it had seen the vulnerability used against real targets. The center did not publish indicators of compromise or attack timelines beyond confirming activity in the wild. Apple has not commented on the scope or origin of the observed attacks.

Both the Engadget and MacRumors reports cite the same NCSC-NL statement as the primary evidence of exploitation. No other vendors or researchers have released independent confirmation at this time.

Why It Matters

Screen Sharing remains a frequently enabled service inside companies and among power users. The short window between the release of 26.6 and the emergency patch in 26.6.1 shows that the flaw was discovered and weaponized quickly. Systems that have not yet installed 26.6.1 continue to expose full remote control to anyone who can reach the port.

Organizations that rely on the feature for internal help-desk work now face a direct choice: apply the update immediately or turn the service off until they can. Individuals who enabled it for occasional access should disable it until the patch is in place. The incident demonstrates that even a narrowly scoped authentication issue in a long-standing macOS service can be turned into complete machine takeover once it is known.

Machines still on macOS Tahoe 26.6 or earlier remain exposed until the update is installed.

---

Sources:

{
  "word_count": 612,
  "sources_used": ["Engadget", "MacRumors"],
  "headline": "macOS Screen Sharing Flaw Now Under Active Attack"
}

No comments yet