logo

From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS

ID: dc95a506-a617-5a00-a16c-34d40a4049a0

STIX ID: report--dc95a506-a617-5a00-a16c-34d40a4049a0

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2026-08-07

Date Updated: 2026-08-19

...
...

This report explains a critical pre-authentication vulnerability in macOS Screen Sharing (CVE-2026-65400) that enables unauthenticated attackers to leverage SSFileCopySender entitlements to read/write files as root and achieve RCE; public PoCs were published, many hosted bare-metal Mac instances are likely exposed, and Apple released patches (macOS 26.6.1, 15.7.9, 14.8.9) with guidance to patch or disable Screen Sharing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.