Apple quietly shipped a security-only update for the Mac on August 6, closing a hole that let anyone on the local network log into Screen Sharing without a password. It is the first patch of its kind for macOS since June, touching every supported version, and researcher Alfredo Pesoli reported the flaw, tracked as CVE-2026-65400, through Bynario Atlas.
The advisory describes an authentication issue fixed with improved state management, with no public sign of exploitation before the patch. The release covers Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, with the Tahoe build weighing about 2.1 GB on Apple silicon.
An authentication bypass reachable over the network tends to draw quick attacker attention once details circulate, so the update deserves priority treatment on any Mac with Screen Sharing or remote management enabled, since the affected component listens for connections directly. Users on older releases should look for the matching Sequoia and Sonoma builds, which carry the identical fix.