Apple released security updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to fix a Screen Sharing vulnerability that could let an attacker on the same network authenticate without valid credentials. The issue appears to primarily affect Macs where Screen Sharing has been explicitly enabled, and Apple said there is no evidence it has been exploited in the wild. Apple also noted that Tahoe 26.6.1 includes broader security fixes available through the standard Software Update mechanism.
The updates follow disclosure of CVE-2026-39875, a CUPS flaw in macOS that allows an unprivileged local user to chain logic bugs in the privileged cupsd daemon and gain an arbitrary file-write capability as root. A public proof-of-concept showed how an attacker could register a malicious printer, capture and replay a valid CUPS authentication token, and abuse a file:// device URI to write to attacker-chosen local paths outside SIP protection. Apple patched affected versions of Sonoma, Sequoia, and Tahoe, and defenders were urged to install updates quickly and watch for suspicious printer registrations, device URI changes, and print jobs targeting file-based destinations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Apple released macOS 26.6.1 Tahoe, macOS 15.7.9 Sequoia, and macOS 14.8.9 Sonoma to fix a Screen Sharing vulnerability that could let a network attacker authenticate without valid credentials. The source says there is no indication the flaw has been exploited in the wild.
On August 6, 2026, Apple released macOS Tahoe 26.6.1 and said the update includes security fixes. The referenced release notes did not identify specific CVEs or affected components.
Security researcher Dallas Dubs released a public proof-of-concept for CVE-2026-39875 showing how two logic flaws in the privileged cupsd daemon can be chained to achieve arbitrary root-owned file writes from an unprivileged local account. The repository includes demonstrations against vulnerable Tahoe 26.4.1, Sequoia 15.7.5, and Sonoma 14.8.5 systems.
Apple addressed CVE-2026-39875, a macOS CUPS vulnerability that allows arbitrary file writes with root privileges, in macOS Tahoe 26.6, Sequoia 15.7.8, and Sonoma 14.8.8. The source does not provide a specific release date for these patches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourceacn.gov.it
Open sourcezdnet.com
Open sourcesecurityweek.com
Open sourcetidbits.com
Open sourcemacrumors.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.