Apple Fixes Screen Sharing Vulnerability in Tahoe, Sequoia, and Sonoma

Could this be because these include other updates and security fixes from the past? For instance, I rarely bother with small .1 updates (I hate rebooting my Macs), so maybe an update like this includes other fixes already released that I haven’t installed. Then my update size would be completely different from another’s.

(It also could be that the newest update requires other updates to already be there for technical reasons.)

Yeah, but that was four days ago. It’s 2026. Anything that happened more than two days ago is “old.” Get with the program!
:wink:

Sure. All those reasons and more. There was a time I would have tried to dig into it, but at this point, if a guy like Howard throws up his hands at it, that’s reason enough for me to stop worrying about it, too.

FWIW, I just installed the update from 15.7.8. to 15.7.9. It didn’t disable screen sharing and it didn’t enable remote management. And I was able to connect from a Windows PC using the RealVNC viewer app without changing any system configuration.

But the article citing the issue was with respect to macOS 26, not 15, so maybe the bug only happens there.

2 Likes

I had the same thing happen with a message of mine in another thread.

Folks, before you post to a thread, check the WHOLE thread to see if your point or question has already been dealt with.

3 Likes

Evidently, within a few hours of Apple releasing 26.6.1, 15.7.9, and 14.8.9, some enterprising miscreants used AI to reverse engineer an exploit against unpatched machines.

By the way, I haven’t seen any information on whether pre-Sonoma versions of macOS, like Monterey or Ventura, are vulnerable. For home users, I believe the risk is low, but if you’re stuck on Monterey, I think we’re at the point where it really shouldn’t be used on public or otherwise untrusted networks.

1 Like

Howard just had another great summary of all that goes into the size estimates for various macOS update downloads/installs and why they sometimes end up disagreeing while you install.

2 Likes

Presumably, the system cryptexes for Intel and Rosetta 2 update will go away next year with macOS 28, so the update sizes will be a bit smaller.

1 Like

Or something else will make it larger.

4 Likes

I hope that this is not an issue on a home network behind a router/firewall. I use Screen Sharing on my Mac Studio (Sequoia) to connect to a headless MacPro5,1 that runs Mojave, Sierra, Mountain Lion, and Snow Leopard – and there are, of course, no updates for those legacy systems.

Ars Technica now reports that this vulnerability is under active exploit.

4 Likes

Most routers block that port by default. So, unless you’ve explicitly opened it in your router you should be fine.

Dave

1 Like

Screen sharing on old versions of MacOS is now a liability, but what about Remote Management, which looks after screen sharing? I use RM routinely to connect to a headless 2012 Mini running Mojave, for iTunes. ( I do have a workaround, but it’s hardware, so clunkier. )

Using Remote Management to access iTunes on a Mac Mini that sits on your local network (LAN) is a bigger wrench than necessary. I do similar with a 2009 iMac running OS X 10.9 and iTunes 12.6.1 via plain old Screen Sharing.

The headlessness of your Mini might trip you up, but there is a solution for that—an HDMI dongle that fools the Mini’s OS regarding there being an attached display. MacSales.com sells one and they may be available elsewhere too.

NewerTech HDMI Headless Display Emulator – MacSales.com

1 Like