What happened
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
Affected versions
macOS: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
CVE-Intel · HORKimhab/CVE-2026-65400CVE-2026-65400ExploitPython★ 3⑂ 1Code indexedUpdated 26 Aug 2026HORKimhab2026-08-18CandidateCVE-Intel · panchocosil/CVE-2026-65400-pocRead-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.BypassPython★ 3⑂ 0Code indexedUpdated 25 Aug 2026Tags: apple, cve-2026-65400, exploit, macos, poc, screen-sharing, security-research, vulnerability-researchpanchocosil2026-08-21CandidateCVE-Intel · acheong08/CVE-2026-65400Apple MacOS Screen Sharing Arbitrary File read/write -> RCERCEPython★ 2⑂ 1Code indexedUpdated 22 Aug 2026acheong082026-08-22CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.