Authentication Vulnerability in macOS Products by Apple
CVE-2026-65400
Key Information:
Badges
What is CVE-2026-65400?
CVE-2026-65400 is an authentication vulnerability identified in Apple's macOS products, specifically impacting Screen Sharing functionalities. The flaw arises from inadequate state management during the authentication process, permitting unauthorized individuals on the network to gain access without valid credentials. This vulnerability is particularly concerning for organizations utilizing macOS systems, as it can facilitate unauthorized control over user sessions, posing significant security risks. The issue has been remediated in recent updates, namely macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, and macOS Tahoe 26.6.1.
Potential impact of CVE-2026-65400
-
Unauthorized Access: This vulnerability potentially allows attackers to bypass authentication requirements, leading to unauthorized access to sensitive user sessions and data. Such access could result in the compromise of confidential information and systems.
-
Data Breach Risks: With unauthorized access, there is a heightened risk of data breaches, where sensitive organizational data could be exposed, stolen, or manipulated, leading to substantial reputational and financial damage.
-
Network Security Compromise: The ability for attackers to authenticate without proper credentials weakens overall network security, potentially leading to further exploitation of connected systems or services, as malicious actors could pivot from the compromised sessions to target additional assets within the network.
Affected Version(s)
macOS 0 < 14.8.9
macOS 0 < 15.7.9
macOS 0 < 26.6.1