{"id":404536,"date":"2026-08-22T02:49:58","date_gmt":"2026-08-22T02:49:58","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=404536"},"modified":"2026-08-22T02:49:58","modified_gmt":"2026-08-22T02:49:58","slug":"mac-screen-sharing-update","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/mac-screen-sharing-update\/","title":{"rendered":"Someone on the Wi-Fi can sit at your Mac. Patch Screen Sharing"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Screen Sharing is the Mac&#8217;s built-in remote desktop. Leave the toggle on, and someone on the same Wi-Fi can try to sit at your keyboard without the password you thought they needed. Apple shipped a fix on 6 August. CISA put the bug on the Known Exploited list on 18 August, with a federal due date of 21 August. If Software Update is still sitting there, the door is still a door.<\/p><div id=\"mwtad3611888037\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-overview.png\" alt=\"MacBook with Screen Sharing turned On in System Settings\" class=\"wp-image-404604\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-overview.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-overview-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-overview-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">Screen Sharing is the door.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad2718520241\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What broke<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Apple&#8217;s security notes for Tahoe, Sequoia, and Sonoma all say the same thing. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. The bug is <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-65400\" target=\"_blank\" rel=\"noopener\">CVE-2026-65400<\/a>. Apple fixed it with improved state management. That is the vendor&#8217;s phrase for the Mac losing track of whether the other side had actually logged in.<\/p>\n\n\n\n<div id=\"mwtad679347262\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p class=\"wp-block-paragraph\">Screen Sharing is the remote-desktop service built into macOS. You turn it on for another Mac across the room, or when a shop admin wants to fix a till from the back office. The password is supposed to be the door. This bug lets the service accept a session without that password. Once the session is in, the other person has a keyboard and whatever is already unlocked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CISA listed the CVE on the <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\">Known Exploited Vulnerabilities catalog<\/a> on 18 August 2026. The row repeats Apple&#8217;s wording and marks ransomware use as Unknown. There is no official victim count. Federal agencies were told to remediate by 21 August.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the network does not mean a random host somewhere on the internet. It means the same Wi-Fi, a cafe, the shop floor, a guest network that was never isolated. A stranger on the coffee-shop network is in range of a Mac that left Screen Sharing on. A random host on the internet is not, unless someone forwarded the Screen Sharing port through the router. Most home routers do not do that by default. A shop that forwarded it for &#8220;remote support&#8221; just made the cafe problem global.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who is in range<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Any Mac still below Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9. If the toggle is on, the service is listening, even if you left it on last year for a one-time remote help session. The front-desk iMac, the laptop in the bag, the till Mac that only runs the register: all of them are in range until About This Mac shows the build.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Updating Safari or Chrome does not patch this. The hole is in the operating system service, not in a browser. iPhone, iPad, and Windows do not run this service. A Mac too old for Sonoma is outside this patch line. Apple did not ship this CVE for Ventura or older.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What the vendor shipped<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/support.apple.com\/en-us\/148170\" target=\"_blank\" rel=\"noopener\">macOS Tahoe 26.6.1<\/a>, 6 August 2026, the Screen Sharing fix on Tahoe<\/li>\n<li><a href=\"https:\/\/support.apple.com\/en-us\/148171\" target=\"_blank\" rel=\"noopener\">macOS Sequoia 15.7.9<\/a>, 6 August 2026, the same CVE on Sequoia<\/li>\n<li><a href=\"https:\/\/support.apple.com\/en-us\/148172\" target=\"_blank\" rel=\"noopener\">macOS Sonoma 14.8.9<\/a>, 6 August 2026, the same CVE on Sonoma<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Tahoe 26.6.2 shipped on 17 August as a later Tahoe security update. That advisory covers other bugs and does not relist this CVE. If About This Mac already shows 26.6.2, you are past 26.6.1, so you already have the fix. 26.6.1 closed this hole. 26.6.2 also counts. The path is Apple menu, System Settings, General, Software Update. Restart if it asks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What this is not<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Not a random internet attack unless Screen Sharing is port-forwarded through the router.<\/li>\n<li>Not an iPhone, iPad, or Windows bug. This service lives on the Mac.<\/li>\n<li>Not patched by updating Safari or Chrome. Those are separate installers.<\/li>\n<li>Not a reason to invent victim counts. CISA listed it as known exploited. Ransomware use is Unknown.<\/li>\n<li>Not done if Software Update still offers 26.6.1, 15.7.9, or 14.8.9. Take the build. Then turn Screen Sharing off if you do not use it.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The patch has been sitting in Software Update since 6 August. Click it on the Mac you are holding, then on the one you do not sit at.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-hero.png\" alt=\"Do This Now card: Patch Screen Sharing, in range You plus the shop, urgency Today, then Software Update\" class=\"wp-image-404535\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-hero.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-hero-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-mac-hero-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">Run Software Update.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad1496367685\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Do This Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In range:<\/strong> You, plus the shop. Any Mac on Tahoe, Sequoia, or Sonoma that missed the 6 August security update.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Urgency:<\/strong> Today. CISA listed CVE-2026-65400 as known exploited. The federal due date was 21 August.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Apple menu, System Settings, General, Software Update. Install what it offers, then restart if it asks.<\/li>\n<li>Confirm the build: Tahoe 26.6.1 or newer (26.6.2 counts), Sequoia 15.7.9 or newer, Sonoma 14.8.9 or newer.<\/li>\n<li>If you do not use Screen Sharing, System Settings, General, Sharing, switch it off. Then do the other Macs in the house.<\/li>\n<\/ol>\n\n\n\n<div id=\"mwtad587135050\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Who can skip<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>About This Mac already shows Tahoe 26.6.1 or newer, Sequoia 15.7.9 or newer, or Sonoma 14.8.9 or newer. Tahoe 26.6.2 also counts.<\/li>\n<li>Windows-only. This service is not on that PC.<\/li>\n<li>iPhone or iPad only. They do not run Screen Sharing.<\/li>\n<li>A Mac too old for Sonoma. Apple did not ship this CVE on that line.<\/li>\n<li>A shop Mac frozen by MDM still needs the 6 August build. That is an IT push, not a skip for the fleet.<\/li>\n<\/ul>\n\n\n\n<div id=\"mwtad1163451837\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Why it matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Screen Sharing is a keyboard. If someone authenticates without the password, they are at your desktop. Mail that is already open. Files on the Desktop. The password manager that unlocked when you sat down. The shop till. The client folder on the designer&#8217;s laptop. You do not need a second exploit story for that to be worth a restart.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CISA adding the row is the in-the-wild signal. Apple did not publish a victim count. The KEV row marks ransomware as Unknown. This brief will not invent either number. The patch has been available since 6 August. People skip Software Update because the Mac looked fine. Looking fine is how a listening service stays a listening service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A cafe Mac with Screen Sharing on is the home case. A shop that forwarded the Screen Sharing port for remote support is the louder case. Either way the click is the same. Take the build. Then turn the service off if you do not need it. The other Mac in the bag is the one people forget. One stale toggle is enough.<\/p>\n\n\n\n<div id=\"mwtad434004221\" class=\"gas_fallback-ad_309751-ad_309691-placement_400593\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3690286463\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The bottom line<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">On this Mac<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Click the Apple menu in the top-left corner. Choose System Settings. On older wording it may still say System Preferences. Same door.<\/li>\n<li>In the left sidebar, click General. Then click Software Update. Stay on that pane. The Mac will check on its own.<\/li>\n<li>If it offers macOS Tahoe 26.6.1, Tahoe 26.6.2, Sequoia 15.7.9, or Sonoma 14.8.9, click Update Now or Restart Now. Enter your Mac password if it asks. Let it finish. Do not close the lid in the middle.<\/li>\n<li>Restart when the pane asks. Sign back in. Click the Apple menu, then About This Mac. Read the version line under the macOS name. You want Tahoe 26.6.1 or newer, Sequoia 15.7.9 or newer, or Sonoma 14.8.9 or newer. Tahoe 26.6.2 from 17 August also counts.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">What you should see<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Software Update first says Checking for updates, then names a build. On Tahoe the Screen Sharing fix is 26.6.1. If the pane already offers 26.6.2, take 26.6.2. You are past the hole either way. On Sequoia the line is 15.7.9. On Sonoma it is 14.8.9. About This Mac repeats that number under the macOS name. Trust that line, not the splash after restart.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">If Software Update will not move<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Stay on a network you already trust. A cafe captive portal can stall the download at 0%. Plug in power. A Mac that is about to sleep will pause the installer. If the pane sits on Checking, quit System Settings from the menu bar, reopen it, and go back to General, Software Update. Do not download a &#8220;macOS updater&#8221; from a random site. Apple&#8217;s own Software Update pane is the installer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A shop Mac managed by MDM or a &#8220;do not update&#8221; catalog will not self-update. Ask whoever owns the image to push Tahoe 26.6.1 or newer, Sequoia 15.7.9, or Sonoma 14.8.9. Same build, different delivery.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Turn Screen Sharing off if you do not use it<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Apple menu, System Settings, General, Sharing. Some builds put Sharing directly in the sidebar. Same list.<\/li>\n<li>Find Screen Sharing. If the switch is on and you do not remote into this Mac, turn it off.<\/li>\n<li>If you do need it, leave it on only after the new build is installed. Then keep it off any network you do not own: cafe Wi-Fi, a hotel, a guest VLAN that was never isolated.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">The other Mac, and when you are done<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The laptop in the bag, the iMac at the front desk, the till Mac that only opens a booking page: same Apple menu path tonight. An iPhone or a Windows PC does not run this service. Skip them for this hole. If a family Mac is too old for Sonoma, it will not be offered 14.8.9. Turn Screen Sharing off there if the toggle exists, and stop.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You are done when About This Mac reads Tahoe 26.6.1 or newer, Sequoia 15.7.9 or newer, or Sonoma 14.8.9 or newer, the Mac has restarted once after the installer, and Screen Sharing is off on every machine that does not need it. You do not need to sign out of iCloud or wipe anything. You needed a new build, and a toggle that was left on. You have both.<\/p>\n\n<div id=\"mwtad2121798314\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Screen Sharing is the Mac&#8217;s built-in remote desktop. Leave the toggle on, and someone on the same Wi-Fi can try to sit at your keyboard without the password you thought they needed. Apple shipped a &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Someone on the Wi-Fi can sit at your Mac. Patch Screen Sharing\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/mac-screen-sharing-update\/#more-404536\" aria-label=\"Read more about Someone on the Wi-Fi can sit at your Mac. Patch Screen Sharing\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":404604,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3605],"tags":[],"class_list":["post-404536","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404536","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=404536"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404536\/revisions"}],"predecessor-version":[{"id":404612,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404536\/revisions\/404612"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/404604"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=404536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=404536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=404536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}