Apple released security updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to fix a Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials. The issue appears to primarily affect Macs where Screen Sharing has been explicitly enabled, and Apple said there is no evidence it has been exploited in the wild. Apple also noted that Tahoe 26.6.1 includes broader security fixes available through the standard Software Update mechanism.
The updates follow disclosure of CVE-2026-39875, a CUPS flaw in macOS that allows an unprivileged local user to chain logic bugs in the privileged cupsd daemon and gain an arbitrary file-write capability as root. A public proof-of-concept showed how an attacker could register a malicious printer, capture and replay a valid CUPS authentication token, and abuse a file:// device URI to write to attacker-chosen local paths outside SIP protection. Apple patched affected versions of Sonoma, Sequoia, and Tahoe, and defenders were urged to install updates quickly and watch for suspicious printer registrations, device URI changes, and print jobs targeting file-based destinations.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
On August 18, 2026, CISA added CVE-2026-65400 to its Known Exploited Vulnerabilities catalog. The listing tied the Screen Sharing flaw to active exploitation relevance after Apple's August 6 macOS security updates.
Apple released macOS 26.6.1 Tahoe, macOS 15.7.9 Sequoia, and macOS 14.8.9 Sonoma to fix a Screen Sharing vulnerability that could let a network attacker authenticate without valid credentials. The source says there is no indication the flaw has been exploited in the wild.
On August 6, 2026, Apple released macOS Tahoe 26.6.1 and said the update includes security fixes. The referenced release notes did not identify specific CVEs or affected components.
A researcher published technical details and an obfuscated ARM64 Go proof-of-concept, "navi_the_clown," for a screensharingd vulnerability the author describes as pre-authentication remote code execution/root compromise on Macs with Screen Sharing enabled. The PoC was said to retrieve arbitrary known-path files such as /etc/sudoers from vulnerable systems without credentials.
The article claims Apple shipped macOS 26.6 on July 27, 2026 with fixes for Screen Sharing bugs, including an earlier pre-authentication flaw in screensharingd that reportedly did not receive a CVE. Researchers cited in the piece describe this as a separate bug from CVE-2026-65400 later fixed on August 6.
Researchers said they reverse engineered Apple’s macOS 26.6.1 Screen Sharing patch and produced a working exploit for CVE-2026-65400 within about four hours. The writeup describes the flaw as a logic bug in screensharingd that can enable unauthenticated network access leading to remote root compromise when Screen Sharing is enabled.
Security researcher Dallas Dubs released a public proof-of-concept for CVE-2026-39875 showing how two logic flaws in the privileged cupsd daemon can be chained to achieve arbitrary root-owned file writes from an unprivileged local account. The repository includes demonstrations against vulnerable Tahoe 26.4.1, Sequoia 15.7.5, and Sonoma 14.8.5 systems.
Apple addressed CVE-2026-39875, a macOS CUPS vulnerability that allows arbitrary file writes with root privileges, in macOS Tahoe 26.6, Sequoia 15.7.8, and Sonoma 14.8.8. The source does not provide a specific release date for these patches.
Apple fixed CVE-2026-28825, an out-of-bounds write in the macOS SMB client kernel component smbfs.kext, in macOS 26.4. Apple said the issue could allow an app to modify protected parts of the file system and addressed it with improved bounds checking.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
cirt.gy
Open sourcecirt.gy
Open sourceheise.de
Open sourcemalware.news
Open sourcesupport.apple.com
Open sourcecybersecuritynews.com
Open sourcereverse.put.as
Open sourceblog.calif.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.