Mobile menu toggle

macOS Tahoe 26.6.1 patches nasty Screen Sharing security hole

By

Why you should install macOS Tahoe 26.6.1 today
Mac users, don't procrastinate on installing macOS Tahoe 26.6.1.
Photo: Tranmautritam/Pexels CC

Apple on Thursday released macOS Tahoe 26.6.1, a surprise security update that fixes a potentially serious vulnerability in the operating system’s Screen Sharing feature.

While the update doesn’t bring any new features, Mac users should nevertheless install it as soon as possible — or the new security patches for macOS Sequoia and Sonoma.  

Why you should install macOS Tahoe 26.6.1 today

Screen Sharing is a macOS feature that lets you view and control another Mac remotely over a local network or the internet. It’s commonly used for troubleshooting, providing technical support, accessing files and apps from another computer, or managing Macs in homes, schools and businesses.

Once connected, Screen Sharing lets you see a remote Mac’s desktop, open applications, transfer files and use its keyboard and mouse as if you were sitting in front of the computer.

It’s definitely not something you want a hacker to be able to do to your Mac without your permission. So you can understand why Apple rushed out macOS Tahoe 26.6.1, even though closing this security hole is the only change it makes.

Without this update, Apple warns that “an attacker on the network may be able to authenticate to Screen Sharing without valid credentials,” a problem the company fixed through improved state management.

Apple didn’t say whether the flaw had been actively exploited in the wild, which the company would have done if it were aware that hackers were already using it.

Note that the Screen Sharing bug also applies to earlier versions of the operating system. That’s why Cupertino introduced security updates for older versions of macOS, including macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

How to install this update

Mac users can install macOS Tahoe 26.6.1 by opening Settings > General > Software Update.

As this is a special-purpose update intended to fix a single security flaw in the operating system for Macs, no new iOS, iPadOS or watchOS versions came out on Thursday.

One response to “macOS Tahoe 26.6.1 patches nasty Screen Sharing security hole”

  1. Gen Z80 says:

    Perhaps CoM can publish a tutorial on how to secure screen sharing. This is done by creating commands to start and stop the daemon from the command line and setting up firewall rules that block access to the incoming ports except from localhost, then using SSH to form a tunnel from the origin computer to the target/host computer that auto-forwards the appropriate ports and, lastly, invoking screen sharing on an address like vnc://127.0.0.1:5800

    In this way, when (not if) these types of vulnerabilities are discovered by bad actors and (often years later, as in this case) patched, it does not have as significant an impact. This technique should really be used with ALL incoming ports on your Mac, not just screen sharing; however, you have to think once, twice and once again before exposing any ports on your Mac to the Internet other than SSH.

    Alas, there have been security issues with SSH as well. What more can you do? Only expose SSH to a VPN and keep the Mac on a private network (not just VLAN) behind the VPN Server.

    Isn’t it interesting that Apple does not inherently allow iPads to connect to the screens of remote Macs (outside of FaceTime or whatever) though this is possible using third-party apps and open source. Some of that could be protecting their laptop sales from being cannibalized by their tablets, but some of it could be security issues — too many people plugging a cable modem into their Mac and enabling ARD/Screen Sharing is a formula for winding up on cable news.

Comments

Your email address will not be published. Required fields are marked *

  • Subscribe to the Newsletter

    Our daily roundup of Apple news, reviews and how-tos. Plus the best Apple tweets, fun polls and inspiring Steve Jobs bons mots. Our readers say: "Love what you do" -- Christi Cardenas. "Absolutely love the content!" -- Harshita Arora. "Genuinely one of the highlights of my inbox" -- Lee Barnett.