From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS

Imported from official source

Cybersecurity Classified by Officially

Apple released patches on July 27 and August 6, 2026 to address vulnerabilities in the macOS Screen Sharing service.

Two distinct Screen Sharing vulnerabilities surfaced within days of each other: CVE-2026-43760 and CVE-2026-65400. They are easy to confuse but differ in the one thing that matters most: whether the attacker needs credentials.

CVE-2026-65400, the more serious of the two, exploits a flaw in the Screen Sharing service's implementation of Secure Remote Password (SRP), which ultimately allows pre-authenticated remote code execution on all supported macOS versions. This means that an attacker could run malicious code on the victim system without having to log in as a root user.

Anybody who leverages Apple's Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately.

* Public PoCs affect versions prior to this.

Acknowledgments: Special thanks to Bryan Masters and Stuart Ashenbrenner for their contributions to this investigation and write-up.

If you're running Screen Sharing on macOS and exposing it to the public internet, then we need to talk. While it's generally frowned upon to expose remote access protocols to the world, we understand that some use cases may require it. You do you!

With the uptick in hosted bare-metal Apple devices, such as the Mac mini available for on-demand workloads, SSH and Screen Sharing are commonly enabled by default on any newly provisioned service.

Apple's security releases announced in the last week of July were followed by a flurry of activity, public disclosures of newly patched bugs, and commentary on the scale of the CVEs listed. With this come references to bugs related to the Screen Sharing server. A week later, Apple  released a patch to comprehensively squash a bug of significant consequence.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/macos-screen-sharing-rce-patched

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
September 20, 2026 19:55
Versions
1 recorded
Identity
https://www.huntress.com/blog/macos-screen-sharing-rce-patched

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.