A flaw in screensharingd 's SRP state handling can leave a stale authentication-success state after frame validation, allowing an unauthenticated RFB session to cross the authentication boundary. Apple patched a flaw allowing network attackers to authenticate to Screen Sharing without valid credentials. Researchers traced it to screensharingd and SRP state handling, with privileged filesystem access and potential RCE paths.