Junglewise Threat Intelligence

CVE-2026-43665: Apple macOS information disclosure in Screen Sharing

CVE-2026-43665 · Severity: info · Published 2026-07-27

Technologies: Apple macOS Sonoma. Vendors: Apple.

Executive brief

A vulnerability in macOS could allow a person with physical or local access to a computer to discover the password used for Screen Sharing. This affects older VNC-style passwords and could allow an unauthorized user to remotely control the system if Screen Sharing is enabled. Apple has released software updates to prevent unauthorized access to this sensitive information.

Technical details

An information disclosure vulnerability existed in macOS Screen Sharing due to insufficient entitlement checks. A local attacker with the ability to execute code on the target system could bypass these checks to retrieve the legacy VNC password configured for remote access. Apple addressed this issue by implementing additional entitlement requirements to restrict access to the password data. The vulnerability is fixed in macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8.

Affected products

  • Apple macOS Sequoia before 15.7.8
  • Apple macOS Sonoma before 14.8.8

Timeline

  • 2026-07-27: disclosed
  • 2026-07-27: advisory

References

Related threats