Security Alert: macOS Screen Sharing Vulnerability
Date:
2026-08-14 19:35:00
Status:
Closed
Brief Description:
A vulnerability previously identified by Apple in patches released on August 6, 2026 is now under active exploitation with confirmed reports of abuse to deploy crypto miner software.
Current Status:
N/A
Services Affected:
Computing Devices
Remote Assistance Service
Full Description:
OVERVIEW
A vulnerability previously identified by Apple in patches released on August 6, 2026 is now under active exploitation with confirmed reports of abuse to deploy crypto miner software.
The vulnerability is a complete authentication bypass via macOS Screen Sharing or Remote Management, which is a superset of controls that includes Screen Sharing. An attacker with network line-of-sight to a vulnerable macOS computer can bypass login requirements without valid user credentials and gain access to the computer.
RECOMMENDATIONS
Apply macOS updates as soon as possible: Update macOS on Mac - Apple Support
Update installation and final restart requires a user password to complete.
Turn off Screen Sharing and Remote Management on unpatched Macs. On an unpatched Mac:
- In the top-left corner of your screen click Apple Menu > System Settings
- Navigate to General > Sharing.
- Disable both/either Screen Sharing and Remote Management.
For Jamf admins of managed endpoints, you can remotely turn off Screen Sharing and Remote Management by either:
- Navigating to an individual Mac in Jamf Pro and sending a Disable Remote Desktop command: Remote Commands for Computers • Jamf Pro Documentation 11.31.0 • Jamf Learning Hub , or
- Creating a group of your impacted Macs and sending a Disable Remote Desktop command as a Mass Action to that group: Mass Actions for Computers • Jamf Pro Documentation 11.31.0 • Jamf Learning Hub
SYSTEMS AFFECTED
macOS computers with either Screen Sharing or Remote Management enabled running any of the versions identified in the table above.
REFERENCES
Enter a full description of the incident. This will appear in the "see all information" view of this alert.
CIT TDX ID:
