Apple Fixes Screen Sharing Vulnerability in Tahoe, Sequoia, and Sonoma

Originally published at: Apple Fixes Screen Sharing Vulnerability in Tahoe, Sequoia, and Sonoma - TidBITS

Apple has released a trio of macOS updates—macOS 26.6.1 Tahoe, macOS 15.7.9 Sequoia, and macOS 14.8.9 Sonoma—to address a vulnerability in Screen Sharing. The release notes say, “An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.”

There’s no indication that this bug has been exploited in the wild. In fact, Apple’s wording suggests to me that Screen Sharing is vulnerable to unauthenticated connections over the local network, not the Internet. Plus, Screen Sharing is turned off by default, so it seems likely that only Macs with it explicitly enabled would be vulnerable. You can check your status in System Settings > General > Sharing > Screen Sharing.

Regardless, the possibility of an unauthenticated user being able to observe or control another Mac via Screen Sharing is sufficiently concerning that I recommend everyone update as soon as is convenient.

5 Likes

Howard Oakley has reported that the actual payload is often much smaller than what Apple’s numbers indicate. Also, isn’t the minimum update size nowadays dictated by the SSV?

3 Likes

Just for the record this did not fix the issue I am experiencing with not being able to use an app like RealVNC to control my Macs after upgrading to 26.6. Makes sense since it’s closing more vulnerabilities, but I had some hope for a little while when I first saw the update available. :)

I don’t think this is urgent for most home users - it seems to be a LAN only attack. Much more important in an enterprise environment.

Could be an issue if you’re traveling. Hotels and other public networks are not really trusted.

But I agree, that on a home network, behind a router/firewall, it’s probably not going to be a big concern.

FWIW, I immediately updated my laptop. I’ll do my desktop systems when I get around to it.

3 Likes

FWIW, the Sequoia 15.7.9 update weighed in at 4.20 GB on my M1 MacBook Air.

It could have been smaller, but it was certainly in the gigabytes range given how long it took to download.

But yes, you’re probably right about the SSV, which would also explain why Apple couldn’t use a Background Security Improvement release

That was certainly the implication of “ An attacker on the network,” but have you seen actual confirmation?

Freaky, given that the 15.7.9 update on my M4 MacBook Pro is only 1.49 GB.

I’ll pile in with a svelte 656.4 MB (on an Intel Mac)…

2 Likes

What were you (each) upgrading from? If you were upgrading from 15.7.8, then it was probably a delta-update. But if you were upgrading from an earlier release, then you probably got a “combo update” containing all the fixes from 15.7.1 through 15.7.9.

In my case, the update was 15.7.8 to 15.7.9.

2 Likes

Interesting – I’ve also got 15.7.8 on my M4 Mac Studio, but I’m showing the 1.49 GB update size, same as @ace:

UPDATE: However, when I actually performed the update to 15.7.9, the download was 4.20 GB, like @josehill :

2 Likes

Same. I was upgrading an M4 MBP from 15.7.8 and it started small 1.5GB, but after a minute or so something reset and it started downloading 4GB. Install was very quick but still required multiple reboots. It’s ridiculous that the numbers can’t even be consistent on the same machine throughout the same update.

1 Like

Someone figured out the changes!

https://discussions.apple.com/thread/256337577?sortBy=rank

Actually I don’t think you need to go into the Remote Management settings as the poster says. I know I tried this with macOS 26.6 and it didn’t work, but now in 26.6.1 you can set the VNC password in the Screen Sharing settings and that fixes things at least for me.

Kind of a bummer losing out on authentication based on the actual users on the machine but for my limited purposes it’s fine.

The link in that message seems to be mangled. Neither my Mac nor iPhone can connect and get a HTTP ERROR 400 Ambiguous URI path separator error. Here is a clean version.

It appears that some of the slash characters were replaced by %2F.

Thanks! I’ve also updated the original post to fix the broken URL.

1 Like

I should never have uncovered the rabbit hole of the update sizes—as with the Finder, they’re just not predictable or understandable from the outside anymore. I’ve pulled that paragraph now.

4 Likes

I vaguely recall Howard Oakley mentioning the unpredictability of update sizes at some point in the last few years. It may be much ado about nothing, but I think it’s a useful reminder for those eagle-eyed individuals who try to analyze everything that happens on their systems. Our Macs are increasingly inscrutable, and there doesn’t seem to be much that can be done about that.

1 Like

I tried reminding folks of that at the very beginning of this thread.

1 Like