Lead story
The Mac Bug That Lets Strangers Log In Without a Password — And It's Being Exploited Right Now
Apple has a serious problem. A vulnerability in macOS's screen-sharing subsystem is under active exploitation, allowing remote attackers to log in to a target machine without providing a password. No phishing required. No credential theft. Just a network path and a bug.
The flaw sits in the Remote Desktop / screen-sharing stack — a component that many Mac users leave enabled for IT support, remote work, or network administration. When it's on and the bug is present, an unauthenticated attacker who can reach the machine over the network can gain full control. Ars Technica, which broke the story, describes it as giving attackers "full control of Macs."
What makes this particularly nasty is the combination of factors: macOS has a reputation — sometimes deserved, sometimes not — for being "more secure" than Windows, which means a meaningful proportion of users have a false sense of comfort. Remote Desktop is on by default in some enterprise and education configurations. And active exploitation means this isn't a theoretical risk — someone is already using it.
The timing matters too. It's a Saturday in August, the tail end of northern hemisphere summer. Security teams are thin. Patch deployment is slower on weekends. Threat actors know this.
What you should do right now: If you're a Mac user with Screen Sharing or Remote Desktop enabled — check System Settings → General → Sharing. Turn off anything you don't actively need. Apply Apple's patch the moment it appears in Software Update if you haven't already. If you're running a fleet of Macs in an organisation, treat this as P1 until patched.
For Australian organisations, this is especially relevant in education and creative industries, where Mac deployments are dense. University IT teams in particular should be checking their remote-access configurations this weekend rather than waiting until Monday. Under the Privacy Act and relevant state government ICT security frameworks, any incident involving unauthorised access to systems carrying personal data triggers mandatory assessment obligations.
The broader pattern is worth noting. Three of the last four weeks have featured a critical, actively-exploited vulnerability in a major consumer platform — Linux containers, Zoom, and now macOS. The pace of exploitation following disclosure (or, worse, before it) is accelerating. Defenders are being asked to move faster than ever on patch cycles, and the window between "bug discovered" and "bug weaponised" continues to shrink.
Watch for Apple's security advisory, which should detail the CVE and affected macOS versions. If your organisation uses any MDM solution — Jamf, Mosyle, Microsoft Intune for Mac — get that patch into your deployment pipeline the moment Apple releases it. Don't wait for the weekly maintenance window.
