Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.world

CVE-2026-65400: macOS Screen Sharing authentication bypass

A flaw in screensharingd 's SRP state handling can leave a stale authentication-success state after frame validation, allowing an unauthenticated RFB session to cross the authentication boundary. Apple patched a flaw allowing network attackers to authenticate to Screen Sharing without valid credentials. Researchers traced it to screensharingd and SRP state handling, with privileged filesystem access and potential RCE paths.

https://wp.me/pfPk8e-5T5Open linkView original on lemmy.world
5

No replies yet

No comments on the original post yet.
CVE-2026-65400: macOS Screen Sharing authentication bypass | Spyke