macOS Critical Security Vulnerability Allows Remote Login Without Password; Apple Releases Patch 26.6.1ME News reports that on August 8 (UTC+8), according to monitoring by Beating, security researcher Calif disclosed a critical security vulnerability (CVE-2026-65400) in macOS’s Screen Sharing feature.
If screen sharing is enabled on a user’s computer, any remote attacker can exploit this vulnerability to log in using any account—without needing to know the password.
The researcher has reverse-engineered Apple’s macOS 26.6.1 patch, identified the root cause and exploitation method, and released a proof-of-concept code.
Apple has patched this vulnerability in macOS 26.6.1.
Until upgrading, users can temporarily mitigate risk by disabling Screen Sharing.
macOS Critical Security Vulnerability Allows Remote Login Without Password; Apple Releases Patch 26.6.1
ME News reports that on August 8 (UTC+8), according to monitoring by Beating, security researcher Calif disclosed a critical security vulnerability (CVE-2026-65400) in macOS’s Screen Sharing feature. If screen sharing is enabled on a user’s computer, any remote attacker can exploit this vulnerability to log in using any account—without needing to know the password. The researcher has reverse-engineered Apple’s macOS 26.6.1 patch, identified the root cause and exploitation method, and released a proof-of-concept code. Apple has patched this vulnerability in macOS 26.6.1. All Mac users should upgrade to this version as soon as possible. A full technical analysis report will be published tomorrow. The vulnerability has been classified as “Critical”—unauthenticated remote code execution allows attackers to gain full control of the desktop, making it one of the most severe types of vulnerabilities in desktop operating systems. There is currently no evidence that this vulnerability has been widely exploited in the wild; however, with the proof-of-concept code now public, the risk to unpatched systems is rapidly increasing. Until upgrading, users can temporarily mitigate risk by disabling Screen Sharing. Click the link below to join Beating’s Feishu AI News Channel for 24/7 real-time monitoring of global AI trends and news. (Source: BlockBeats)