[CIVN-2026-0398] Authentication Bypass Vulnerability in Apple macOS

By Published On: August 11, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Authentication Bypass Vulnerability in Apple macOS


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


MacOS Sonoma versions prior to 14.8.9

MacOS Sequoia versions prior to 15.7.9

MacOS Tahoe versions prior to 26.6.1

Overview


A vulnerability has been reported in Apple macOS that could allow an attacker on the network to authenticate to screen sharing without valid credentials on the targeted system.


Target Audience:

Individuals and organizations using the affected versions of Apple macOS.


Risk Assessment:

High risk of unauthorized access and sensitive data disclosure.


Impact Assessment:

Potential for compromise on confidentiality and integrity of the system.


Description


Apple macOS is an operating system developed by Apple Inc. for Mac computers. It is designed to provide a secure, efficient, and seamless computing experience on Apple Mac computers.


A vulnerability has been reported in Apple macOS due to authentication issue in Screen Sharing.


Successful exploitation of this vulnerability could allow an attacker on the network to authenticate to Screen Sharing without valid credentials on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://support.apple.com/en-us/148170


https://support.apple.com/en-us/148171


https://support.apple.com/en-us/148172



Vendor Information


Apple

https://support.apple.com/en-us/148170

https://support.apple.com/en-us/148171

https://support.apple.com/en-us/148172


References


Apple

https://support.apple.com/en-us/148170

https://support.apple.com/en-us/148171

https://support.apple.com/en-us/148172


CVE Name

CVE-2026-65400




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7DzwACgkQ3jCgcSdc

ys+B2g//TOBaZV2R9jRUXx9Z/XbRcZKljvnQd5P//gbL5KWeIyvXiRSSwCoI5D/x

XvUomed2zsrz5Si7xSjodsN4QzNtnL/UMYlTQvQSpVIo8Lr3xNqbRpIc+lyM/FkG

3znRDQgYXcgbYaJIDzEftTsp0tm0/TBSI4VfnYXVPC++iAeUc2oNFVzPUrGLSdPz

fPzi6EUm7TcD+FfXn677WpGtSmFs5DM1dc/RyFkNpx6SN8QC1F5BaJJHcu1EuHAR

xdjI6FDjKLMU/kIWSDIqyNzUQIxVUh+R2G1b+QcGqRyfE/7eyK59YMuV23ov/J52

vX4ZenF+5F6JvnNjLI26EA2hK6gIu1jaSYgvahBCpV4SgE3T+Ed33i4zl6MkIx8E

51Fqg+1wxymR1D/uZslbrOJPxMvyslxwadwLSsjisCaVvh+qst5JIhUj14cKzj2W

7XaPFjFideQ7//2fC7sAp0KILhmhCbfOk0eWOH8DR9wMIHJXQ87o5gMfAyRvZY7u

kPfCtMJ7KyeO2DK7iPWxus8W0hAlPNS1B4vyPPS8cieyBqlsylzGAa0oin8lDFjM

oPbvtEGisWMXjsGQSXywOA/Q/jfY55dhXv/xG1AYV0JoaZrmKZqRQBhVuId0rRDW

2+FcgH3HqaPH+aH9LDXrksZypliF+bLvmRcle0akJWNsph5v7DY=

=3DZX

—–END PGP SIGNATURE—–

Share this article