Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise
Intro#
In late July 2026, a cluster of vulnerabilities in macOS Screen Sharing turned what initially looked like a fairly constrained privilege problem into one of the more interesting macOS remote-attack stories in years.
The public discussion actually covers several different bugs inside screensharingd, and they are easy to conflate. One required a legacy VNC password, another allowed authentication to be bypassed entirely, and a third related pre-authentication flaw forced Apple to ship an unusual out-of-band macOS update only days later.
...
The full blog was published at my company's (Iru, formerly Kandji) website: https://www.iru.com/blog/inside-the-screensharingd-bugs-how-macos-screen-sharing-went-from-root-file-access-to-pre-auth-compromise