CVE-2026-43665

Summary

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.

Affected Software

VendorProductVersion RangeStatus
ApplemacOS0 < 14.8.8affected
ApplemacOS0 < 15.7.8affected

Weaknesses

  • A local attacker may be able to determine the legacy VNC password configured for Screen Sharing

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References