
[CIVN-2026-0398] Authentication Bypass Vulnerability in Apple macOS
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Authentication Bypass Vulnerability in Apple macOS
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
MacOS Sonoma versions prior to 14.8.9
MacOS Sequoia versions prior to 15.7.9
MacOS Tahoe versions prior to 26.6.1
Overview
A vulnerability has been reported in Apple macOS that could allow an attacker on the network to authenticate to screen sharing without valid credentials on the targeted system.
Target Audience:
Individuals and organizations using the affected versions of Apple macOS.
Risk Assessment:
High risk of unauthorized access and sensitive data disclosure.
Impact Assessment:
Potential for compromise on confidentiality and integrity of the system.
Description
Apple macOS is an operating system developed by Apple Inc. for Mac computers. It is designed to provide a secure, efficient, and seamless computing experience on Apple Mac computers.
A vulnerability has been reported in Apple macOS due to authentication issue in Screen Sharing.
Successful exploitation of this vulnerability could allow an attacker on the network to authenticate to Screen Sharing without valid credentials on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://support.apple.com/en-us/148170
https://support.apple.com/en-us/148171
https://support.apple.com/en-us/148172
Vendor Information
Apple
https://support.apple.com/en-us/148170
https://support.apple.com/en-us/148171
https://support.apple.com/en-us/148172
References
Apple
https://support.apple.com/en-us/148170
https://support.apple.com/en-us/148171
https://support.apple.com/en-us/148172
CVE Name
CVE-2026-65400
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7DzwACgkQ3jCgcSdc
ys+B2g//TOBaZV2R9jRUXx9Z/XbRcZKljvnQd5P//gbL5KWeIyvXiRSSwCoI5D/x
XvUomed2zsrz5Si7xSjodsN4QzNtnL/UMYlTQvQSpVIo8Lr3xNqbRpIc+lyM/FkG
3znRDQgYXcgbYaJIDzEftTsp0tm0/TBSI4VfnYXVPC++iAeUc2oNFVzPUrGLSdPz
fPzi6EUm7TcD+FfXn677WpGtSmFs5DM1dc/RyFkNpx6SN8QC1F5BaJJHcu1EuHAR
xdjI6FDjKLMU/kIWSDIqyNzUQIxVUh+R2G1b+QcGqRyfE/7eyK59YMuV23ov/J52
vX4ZenF+5F6JvnNjLI26EA2hK6gIu1jaSYgvahBCpV4SgE3T+Ed33i4zl6MkIx8E
51Fqg+1wxymR1D/uZslbrOJPxMvyslxwadwLSsjisCaVvh+qst5JIhUj14cKzj2W
7XaPFjFideQ7//2fC7sAp0KILhmhCbfOk0eWOH8DR9wMIHJXQ87o5gMfAyRvZY7u
kPfCtMJ7KyeO2DK7iPWxus8W0hAlPNS1B4vyPPS8cieyBqlsylzGAa0oin8lDFjM
oPbvtEGisWMXjsGQSXywOA/Q/jfY55dhXv/xG1AYV0JoaZrmKZqRQBhVuId0rRDW
2+FcgH3HqaPH+aH9LDXrksZypliF+bLvmRcle0akJWNsph5v7DY=
=3DZX
—–END PGP SIGNATURE—–


