Description
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Apple / macOS0 – 14.8.9
- Apple / macOS0 – 15.7.9
- Apple / macOS0 – 26.6.1
- Apple / macOS14.0 – 14.8.9
News coverage
- Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationThe Hacker News · 9d ago
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero MinerThe Hacker News · 13d ago
References
- VENDOR_ADVISORYhttps://support.apple.com/en-us/148170
- VENDOR_ADVISORYhttps://support.apple.com/en-us/148171
- VENDOR_ADVISORYhttps://support.apple.com/en-us/148172
Updated 6m ago · 8 sources