DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Apple Screen Sharing Pre-Auth RCE

Quality: 8/10 Relevance: 9/10

Summary

A critical pre-authentication vulnerability in Apple's Screen Sharing service (screensharingd) affects macOS <= 26.5. The bug bypasses SRP key exchange, leaving the RFB session in the clear and enabling root file read/write via the Apple file-copy protocol; remediation is to patch to macOS 26.6 or disable Screen Sharing. The article includes attack details, PoC, and a second SRP weakness.

🚀 Service construit par Johan Denoyer