Skip to main content

Security Alert: macOS Screen Sharing Vulnerability

Date:
2026-08-14 19:35:00
Status:
Closed
Brief Description:
A vulnerability previously identified by Apple in patches released on August 6, 2026 is now under active exploitation with confirmed reports of abuse to deploy crypto miner software.
Current Status:
N/A
Services Affected:
Computing Devices
Remote Assistance Service
Full Description:
OVERVIEW
A vulnerability previously identified by Apple in patches released on August 6, 2026 is now under active exploitation with confirmed reports of abuse to deploy crypto miner software.


The vulnerability is a complete authentication bypass via macOS Screen Sharing or Remote Management, which is a superset of controls that includes Screen Sharing. An attacker with network line-of-sight to a vulnerable macOS computer can bypass login requirements without valid user credentials and gain access to the computer.
 
RECOMMENDATIONS
Apply macOS updates as soon as possible: Update macOS on Mac - Apple Support
Update installation and final restart requires a user password to complete.


Turn off Screen Sharing and Remote Management on unpatched Macs. On an unpatched Mac:
  1. In the top-left corner of your screen click Apple Menu > System Settings
  2. Navigate to General > Sharing.
  3. Disable both/either Screen Sharing and Remote Management.

For Jamf admins of managed endpoints, you can remotely turn off Screen Sharing and Remote Management by either:
  1. Navigating to an individual Mac in Jamf Pro and sending a Disable Remote Desktop command: Remote Commands for Computers • Jamf Pro Documentation 11.31.0 • Jamf Learning Hub , or
  2. Creating a group of your impacted Macs and sending a Disable Remote Desktop command as a Mass Action to that group: Mass Actions for Computers • Jamf Pro Documentation 11.31.0 • Jamf Learning Hub


SYSTEMS AFFECTED
macOS computers with either Screen Sharing or Remote Management enabled running any of the versions identified in the table above.
 
REFERENCES
Enter a full description of the incident. This will appear in the "see all information" view of this alert.
CIT TDX ID: