Skip to content

Product1 publisher2 min readPublished

Apple patches a Screen Sharing flaw that hands network attackers root on an unpatched Mac

Apple's emergency macOS update on August 6 fixed a Screen Sharing flaw that calif.io turned into a working exploit about four hours later. The flaw let anyone on the network sign in without a password, and the service answering those connections runs as root.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Apple patches a Screen Sharing flaw that hands network attackers root on an unpatched Mac
Generated illustration

What happened

  • A researcher counted around 40,000 Macs exposing Screen Sharing directly to the public internet, each reachable by whoever finds it.
  • The fix shipped out of band as macOS 26.6.1, with matching Sonoma 14.8.9 and Sequoia 15.7.9 releases for older systems.
  • calif.io, which rebuilt the exploit, calls the bug the first public macOS remote root it can find in a long time.
  • A more powerful flaw in the same service had been found earlier by the researcher known as @osxreverser, who chose not to report it to Apple.
  • On July 29 Bynario published a separate Screen Sharing flaw, CVE-2026-43760, a post-auth root bug it found with an automated GPT-5.5 workflow.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Apple's July notes listed three Screen Sharing Server fixes and marked none pre-auth, so an admin judging how fast to patch had no hint a remote root was in the batch.
  • precedent A full writeup of the exploit is already public and was produced with AI, so reproducing the attack no longer depends on finding the bug yourself.
  • contradiction calif.io's account and Apple's record diverge: the firm says a pre-auth remote root was quietly fixed in July, that fix still has no CVE, and Apple has not said whether it knew.

Screen Sharing is the feature you switch on to run a Mac mini in a closet, or to fix a Macbook in another building without walking over to it [3]. Signing in normally takes an account name and a password [4].

A flaw that lets someone through before the password check is called pre-auth [6]. Because that one process answers with full privileges, the intruder does not stop at a single login: it can reach every other account on the machine and install what it wants [8].

The emergency release was the second critical fix in that one program, not the first [10]. Apple had already closed @osxreverser's earlier flaw on July 27, inside macOS 26.6, while fixing the less serious bugs other researchers had reported [12].

When Bynario's bug drew attention, @osxreverser objected that it was the lesser problem and that the real one was a reliable pre-auth remote root [19]. "It's a pre-auth, stupid!" he posted, and declined to describe the flaw itself [18][20]. His complaint pushed researchers back through the same code, where the second flaw turned up and became the emergency fix [27].

From that post to the emergency patch is eight days, a stretch when the pre-auth root was being discussed in the open and no fix had shipped [26]. The fix is credited to Alfredo Pesoli of Bynario, the researcher whose July report had opened the whole thread [24][25].

The person who has to act is whoever turned Screen Sharing on and left it reachable from outside the local network. Two questions settle which machines are urgent: can this one be reached from the public internet, and has it taken the August update. A machine that is reachable and still unpatched is the one at risk.

What to watch

  • Whether Apple states if it knew it had closed a pre-auth remote root in July's 26.6.
  • Whether the roughly 40,000 internet-exposed Macs shrinks as the emergency patch spreads.
  • Whether @osxreverser's first, unreported flaw is ever assigned a CVE.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories