Mac Screen-Sharing Bug Enables Passwordless Remote Access
A recent vulnerability in popular screen‑sharing software has been identified that allows remote attackers to gain full control of a victim’s computer without requiring a password. The flaw, present in the latest update of the widely used application, exploits a flaw in the authentication handshake that permits an unauthenticated user to establish a session once the target has accepted a screen‑share invitation. Security researchers have demonstrated that by sending a specially crafted request, an attacker can bypass the login prompt and execute arbitrary commands on the host machine, potentially exposing sensitive data and compromising the system.
The discovery has prompted the vendor to release an emergency patch and issued a warning to all users to update immediately. Cyber‑security firms note that the issue is similar to past authentication bypass incidents, underscoring the importance of multi‑factor authentication and strict invitation‑management policies. While the software’s support team has confirmed that the patch mitigates the risk, experts advise organizations to review their remote‑access protocols and monitor for unusual login attempts to prevent exploitation of the bug.