Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Apple Patches Mac Flaw That Let Attackers Bypass Screen Sharing Login

Apple shipped surprise security updates on Thursday, August 6, for three versions of macOS after finding a bug that could let an attacker hijack a Mac's Screen Sharing feature without ever entering a password.
The fix landed as macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, according to ZDNET. All three patch the exact same flaw, tracked as CVE-2026-65400.
Apple's own security notes, cited by 9to5Mac, describe the problem in plain terms: an authentication issue that Apple fixed with improved state management. In other words, someone on your network could authenticate to Screen Sharing without valid credentials.
What that actually means for your Mac
Screen Sharing is the built-in tool that lets one Mac remotely view and control another. It normally requires a real username and password before anyone gets in.
This bug broke that requirement. An attacker who's already on the same network, your home Wi-Fi, an office LAN, or especially an open public network like a coffee shop hotspot, could potentially get into Screen Sharing without ever proving they belong there, according to ZDNET.
Lifehacker put it bluntly: this could let hackers activate Screen Sharing without permission, exposing whatever is on your display to anyone in the know. Depending on session privileges, 9to5Mac reported, an attacker could go further than just looking, potentially opening apps, digging through files, or taking other actions on the machine.
Apple credited the discovery to researcher Alfredo Pesoli, working through Bynario Atlas, according to 9to5Mac's rundown of the official security notes.
No confirmed attacks, but caution is warranted
Apple did not say this flaw was ever exploited in the wild, and none of the reporting claims a confirmed real-world victim. ZDNET, Lifehacker, and 9to5Mac all note the same thing: no known attacks have surfaced using this bug.
That's a legitimate reason not to panic. Exploiting this requires an attacker to already have network access, which is a real barrier on a locked-down home or office network with a strong Wi-Fi password. It's a much smaller lift on public Wi-Fi with no protections.
Lifehacker also raised an angle worth considering: modern AI systems are increasingly good at finding these kinds of vulnerabilities on their own, which means it's plausible someone besides Apple's own team could have stumbled onto this bug before a patch existed. That's speculation, not evidence anyone did, but it's a reasonable reason to patch promptly rather than wait.
This is the second Screen Sharing scare in two weeks
Digital Trends flagged something the other outlets glossed over: this isn't Apple's first Screen Sharing patch this summer. macOS 26.6, released July 27, already fixed three separate Screen Sharing Server vulnerabilities, each with its own CVE, according to Digital Trends' review of Apple's security notes.
CVE-2026-43779 could let an app intercept network connections meant for another process. CVE-2026-43777 covered a remote denial-of-service risk. CVE-2026-43760 could let an app grab sensitive user data.
Those three bugs are unrelated to this week's authentication flaw, Digital Trends noted. They're different vulnerabilities with different consequences, not three tries at fixing the same hole. But four Screen Sharing bugs patched across two releases in under two weeks is a pattern worth noticing, not routine maintenance to shrug off.
How to update
Open System Settings, click General, then Software Update. Let it find the patch, then hit Update Now.
You don't need to be on the newest macOS Tahoe to get protected. Apple built the fix for Sequoia and Sonoma too, so anyone running one of the last three major macOS releases can patch today.
What's still unknown
Apple hasn't said how long the flaw existed before Pesoli found it, or whether the underlying authentication weakness might touch other remote-access features beyond Screen Sharing. Apple also hasn't detailed whether enabling two-factor protections or firewall rules would have blocked exploitation even without the patch. Until Apple or independent researchers publish more, the safest assumption is that anyone with Screen Sharing enabled on a shared or public network was exposed until they installed Thursday's update.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.