Apple Mac Screen Sharing flaw exposes thousands of devices: update now or turn it off
Apple has released an urgent macOS security update for a serious Screen Sharing vulnerability that can let an attacker connect without valid login credentials. The issue is especially concerning because changing your password does not fix it. The flaw happens before normal authentication, meaning the attacker may not need your password at all.
The update arrived on August 6 and fixes a single security issue affecting Screen Sharing. Apple rarely ships an out-of-band macOS update for just one flaw, which makes this release stand out. The affected versions are macOS Tahoe before 26.6.1, macOS Sequoia before 15.7.9, and macOS Sonoma before 14.8.9.
Security agencies later raised the alarm. The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its list of actively exploited flaws and ordered federal agencies to patch quickly. The severity rating also increased from 7.1 to 9.8 out of 10 after the risk was reassessed.
Why changing your Mac password will not protect you
Screen Sharing allows a user to view and control a Mac remotely. Normally, you enable the feature, choose who can connect, and rely on a password or authorized account to keep others out.
That protection does not work in this case.
The vulnerability occurs before the authentication step. Because of that, changing the password, removing allowed users, or disabling legacy VNC access is not enough. If Screen Sharing is enabled on a vulnerable Mac, the safe choices are simple: install the latest macOS update or turn Screen Sharing off.
Which Macs are affected?
Macs running macOS Tahoe before version 26.6.1 are affected if Screen Sharing is enabled. Users should update to macOS Tahoe 26.6.1.
Macs running macOS Sequoia before version 15.7.9 are affected if Screen Sharing is enabled. Users should update to macOS Sequoia 15.7.9.
Macs running macOS Sonoma before version 14.8.9 are affected if Screen Sharing is enabled. Users should update to macOS Sonoma 14.8.9.
Macs running macOS Ventura or older do not appear to have a patch available for this specific issue. If you are using one of these older systems, the safest action is to turn Screen Sharing off.
If Screen Sharing is already off, the vulnerability is not exposed through that feature.
If you recently restored a Mac from an older backup or recovery image, update macOS before connecting it to a network whenever possible.
Thousands of Macs may be exposed online
Security scans in early August found roughly 40,000 Macs reachable over the internet with Screen Sharing exposed. Nearly half were reportedly located in the United States, and many appeared to be on residential internet connections rather than business networks.
That matters because this is not only a corporate security problem. Many home users enable remote access once, often for convenience, then forget it is still running. If port 5900 is open to the internet, attackers may be able to find the Mac through automated scanning.
A home router helps, but it is not a complete defense
Many attacks focus on Macs with port 5900 exposed directly to the internet. However, the vulnerability is not limited only to internet-facing systems.
Apple’s description refers to an attacker “on the network.” That can include someone on the same Wi-Fi network, a compromised device inside your home, or a device connected to an office or guest network.
In simple terms, your router may block random internet scanners if you have not configured port forwarding. But it will not protect you from every threat inside the same local network.
What attackers do after breaking in
Installing the macOS update closes the vulnerability, but it does not automatically remove anything an attacker may have already installed.
Security researchers have observed attackers using Screen Sharing access to place scripts and SSH keys on compromised Macs. This gives them a way back in even after the original flaw is patched.
In some cases, attackers also cleaned logs and command history, changed packet filter settings, and installed XMRig, a Monero cryptocurrency miner. The malware was reportedly hidden under a path designed to look less suspicious and disguised as an Apple-like system process named com.apple.airportd. It was then configured through a LaunchDaemon with KeepAlive enabled, allowing it to restart automatically after a reboot.
That means a Mac that was already compromised may remain compromised after updating.
What Mac users should do now
First, check whether Screen Sharing is enabled. Open the Apple menu, go to System Settings, choose General, then open Sharing. Scroll through the list and look for Screen Sharing. If it is switched off, this specific Screen Sharing issue is not exposed.
Second, check Remote Management on the same Sharing page. This is another remote access feature and should be disabled unless you intentionally use it. Screen Sharing and Remote Management cannot normally be enabled at the same time, but it is still worth checking.
Third, install the latest macOS update. The fixed versions are macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.
Fourth, if you use macOS Ventura or an older version, disable Screen Sharing because a patch is not available for those older releases.
Fifth, if your Mac had Screen Sharing exposed to the internet, especially through port 5900, do not assume updating is enough. Review SSH keys, LaunchDaemons, suspicious background processes, firewall rules, and recently modified files. Rotate important passwords and credentials. If you need certainty, back up essential files carefully and perform a clean reinstall.
If you really need Mac remote access
Leaving Screen Sharing open to the internet is risky. If you must use remote access, place it behind a VPN or restrict it with strict firewall rules so only trusted devices can connect.
For most users, the safest option is to keep Screen Sharing turned off unless it is actively needed. This vulnerability is a reminder that convenience features can become serious security risks when they are exposed and forgotten.






