Apple Rushes Out a Fix for a Mac Screen Sharing Security Hole

Apple released security updates for macOS Tahoe, Sequoia, and Sonoma on 6 August 2026 to fix a flaw in a feature called Screen Sharing that could let someone on the same network log into a Mac without a valid password. The affected versions are macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, all listed on Apple's security releases page under the same date. The Screen Sharing flaw is the only issue addressed in this round.
Screen Sharing is a built-in Mac feature that, when turned on, lets someone view and control a Mac's screen from another computer on the same network. Apple's advisory says the vulnerability allowed an attacker on the local network to connect to Screen Sharing without supplying legitimate login details. In plain terms, that means an attacker could gain control of the desktop on any affected Mac where Screen Sharing is turned on. Apple's security content pages for each release (Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9) are live on the company's support site.
These updates did not go through Apple's usual testing process, where new software is first shared with developers and public testers. The company went straight to a general release, a path it reserves for security issues it considers urgent enough to skip that step (Engadget).
This release lands just over a week after Apple's broader July 2026 security update, which shipped on 27 July and addressed 210 separate security flaws across iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and Safari (ZDI). That earlier round patched macOS down to versions .8 in the Sequoia and Sonoma lines. This new push moves the same two older generations to .9, alongside a fresh Tahoe point release at 26.6.1.
The decision to patch across three macOS generations follows Apple's established pattern of providing security updates for multiple major versions at the same time. Tahoe is the current major release, Sequoia is the prior generation, and Sonoma is two generations back. Administrators running mixed fleets should note that all three lines received the fix on the same day, though the build numbers differ: Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9.
The broader context here is what this flaw means in practice. An attacker who can connect to Screen Sharing without a password could take over the desktop of any affected Mac where the feature is turned on, and in many workplaces and schools, Screen Sharing is enabled so IT staff can provide remote support. The attacker needs to be on the same local network as the target Mac, not on the open internet, which narrows the threat. But "on the network" can include any compromised device on the same segment, a guest Wi-Fi connection that reaches into a corporate network, or a pivot through an already-breached machine. In a network without internal barriers, that surface can extend quite far.
Skipping the usual testing process adds a wrinkle for IT teams, who normally get a window to test updates before rolling them out to everyone. Without that window, the usual staged approach gets compressed. The single-patch scope helps: rather than checking a broad set of fixes, teams need only confirm that the Screen Sharing update does not disrupt existing remote management workflows. Still, deploying without pre-testing carries its own risk, and organizations that depend on Screen Sharing for help-desk operations will want to verify that the service still works correctly before a full rollout.
The fact that Apple shipped this outside its normal schedule, ten days after a large 210-flaw update, tells us the company treated the Screen Sharing bypass as time-sensitive. We do not have a tracking number for the flaw, confirmation that it was exploited in the wild, or attribution from the verified sources. What we do have is a patch for a login bypass in a remote access feature, released with minimal preamble across three supported macOS generations.
For administrators, the guidance is straightforward: identify all Macs running Tahoe, Sequoia, or Sonoma with Screen Sharing enabled, prioritize those on shared or low-trust networks, and deploy 26.6.1, 15.7.9, or 14.8.9 respectively. Given the type of vulnerability, this is one to patch quickly rather than waiting for the next routine update cycle.


