top of page
Search

Apple fixes critical macOS vulnerability that allowed remote system access without a password

Aug 24
2 min read

Apple has promptly patched a critical vulnerability in macOS that could have allowed attackers to remotely compromise systems without a password.

The vulnerability was reported by experts at the National Cyber Security Centre of the Netherlands (NCSC). Tracked as CVE-2026-65400, it received a CVSS score of 9.8 out of 10, placing it in the critical severity category and making it an issue that should be addressed immediately.

The flaw is described as an improper state-management issue during the authentication process. Attackers could exploit it to compromise a system and gain remote access while bypassing authentication mechanisms. Under normal circumstances, macOS should prevent such unauthorized access attempts.

CVE-2026-65400 was first discovered in early August. About a week ago, researchers at the Dutch cybersecurity center obtained evidence that a working proof-of-concept exploit was being freely distributed online.

The vulnerability affects macOS Sequoia, Sonoma, and Tahoe. Apple has addressed the issue in versions 15.7.9, 14.8.9, and 26.6.1, respectively.

Attackers have reportedly been using the proof-of-concept exploit to compromise a large number of Mac systems through port 5900, which remains accessible when the Screen Sharing feature is enabled.

Cybercriminals have already exploited the vulnerability to gain access to macOS systems and install a cryptocurrency-mining Trojan targeting Monero. However, the consequences could have been much more serious, as root-level access effectively bypasses the operating system's security protections and allows attackers to install virtually any type of malicious software.

Apple has released security updates for all affected macOS versions, with separate advisories covering Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The company also credited Alfredo Pesoli, who was the first to discover the vulnerability.

Pesoli is the co-founder and CEO of cybersecurity company Bynario, a startup developing AI-powered systems for automated vulnerability detection. Pesoli also said that one of the company's products, called Atlas, will help identify vulnerabilities similar to this one in the future.


 
 
bottom of page