Flash News

macOS exposure high-risk loophole: remote login without password on screen shared, Apple repaired, 26.6.1 recommended upgrade

According to news from 9 August, a security researcher, Calif, sent a message that revealed a serious security loophole in the MacOS screen sharing function (CVE-2026-65400). If a user computer has access to screen sharing, any cyber attackor can use the loophole to log in to a computer using any account, without any need to know the password. The researchers carried out reverse engineering of the MacOS 26.6.1 patches issued by Apple, identified the underlying causes of the gaps and used the methodology and issued the concept validation code. Apple has repaired this loophole in version MacOS 26.6.1, and all Mac users should upgrade the system to that version as soon as possible. A full technical analysis report will be published tomorrow. The loophole is located at the "Critical" level - remote code execution without authentication means that the assailant can obtain complete desktop control and is one of the most serious types of security holes in the desktop operating system. There is currently no evidence that the loophole is being widely used in the physical environment, but the risks to systems without patches are rapidly increasing, given the disclosure of the concept validation code. If the user is temporarily unable to upgrade, closing the screen share before the upgrade can be used as a temporary mitigation measure。

OKX - Unlock Rewards