Tech

A screen-sharing flaw is letting attackers take full control of Macs. Here is what to know

Ars Technica2 h ago
A laptop computer with a digital security icon
A laptop computer with a digital security iconPhoto: Dan Nelson / Pexels

A newly disclosed vulnerability affecting macOS is being actively exploited in the wild, according to security researchers who say the flaw allows remote attackers to gain full administrative control of an affected Mac without ever entering a password. The vulnerability lies in the operating system's screen-sharing feature, a built-in tool that lets one Mac remotely view and control another, typically used for tech support or remote work purposes.

The flaw stems from an authentication weakness in how the screen-sharing service handles login requests under specific configurations. Researchers who identified the exploit describe it as a logic error that allows an attacker to bypass the standard password prompt entirely under certain conditions, gaining the same level of access a legitimate user would have after successfully authenticating. Once inside, an attacker effectively has the same control over the machine as someone sitting in front of it, including the ability to install software, access files and potentially move laterally to other devices on the same network.

What makes this class of vulnerability particularly serious is the authentication bypass itself, rather than any need for the attacker to guess or steal a password. Traditional remote access attacks typically rely on stolen credentials, weak passwords, or tricking a user into approving a malicious connection. A pure authentication bypass removes that barrier entirely, meaning even Mac users with strong, unique passwords are not protected against this specific attack vector if their system is otherwise exposed and vulnerable.

Security researchers say the exploitation observed so far appears targeted rather than opportunistic mass scanning, though they caution that proof-of-concept exploit code circulating in security research circles increases the risk that less sophisticated attackers could begin using the technique more broadly. Once technical details of a vulnerability like this become public, the gap between initial targeted exploitation and widespread opportunistic attacks typically narrows quickly.

The primary exposure applies to Macs with screen-sharing enabled and reachable from outside a trusted local network — a configuration more common in some professional and enterprise settings than in typical home use, where routers usually block unsolicited inbound connections by default. Macs with screen sharing disabled, or those accessible only from within a private local network, face substantially lower risk, though researchers note that any machine on a network where an attacker has already gained a foothold could still be vulnerable to lateral movement.

Apple has been notified of the vulnerability and, as of the disclosure, is understood to be developing a fix, though the company has not published a detailed timeline for a patch. In the interim, security researchers recommend that Mac users and IT administrators check whether screen sharing is enabled on any system that does not strictly require it, and disable the feature on machines where it is not actively in use, particularly on devices with any exposure to the public internet.

For organizations that rely on remote screen sharing for legitimate business purposes, such as IT support teams managing distributed fleets of Mac devices, the immediate mitigation typically recommended is restricting access through a virtual private network or firewall rules that limit which IP addresses can reach the screen-sharing service, rather than leaving it broadly accessible. This does not eliminate risk entirely, since attackers who compromise a device already inside the trusted network can still exploit the vulnerability, but it substantially narrows the pool of potential attackers who can reach the exposed service in the first place.

The vulnerability adds to a broader pattern of attention on macOS security that has intensified as the platform's enterprise adoption has grown. For years, macOS carried something of a reputation, not entirely deserved even at the time, for facing fewer serious security threats than Windows, largely reflecting its smaller historical market share rather than any inherent security advantage. As Mac adoption has expanded significantly in corporate environments, attackers have correspondingly increased their focus on macOS-specific vulnerabilities, a trend security researchers say is likely to continue as the platform's install base grows.

Until Apple ships an official patch, security researchers' guidance remains straightforward: audit whether screen sharing is genuinely necessary on any given machine, disable it where it is not, and restrict network-level access to the service on machines where it must remain active. Users are also advised to keep an eye on official Apple security advisories for the patch, and to apply it promptly once it becomes available, given the severity of the access an attacker can gain through this specific flaw.

This article is an AI-curated summary based on Ars Technica. The illustration is a stock photo by Dan Nelson from Pexels.

Read next