Tech

Critical macOS Screen Share Vulnerability Patched by Apple

Apple has released a crucial security patch for macOS to address a severe vulnerability within its Screen Share functionality. This flaw, identified as CVE-2026-65400, could enable malicious actors on a network to remotely seize complete control of a Mac device without requiring any authentication. Cybersecurity researchers have already observed this exploit being used in the wild, highlighting the urgency for all Mac users to update their operating systems to the latest available version.

Urgent macOS Update Resolves Critical Screen Share Vulnerability

In a significant move to bolster user security, Apple recently deployed a critical update for its macOS operating system. This patch specifically targets a serious vulnerability (CVE-2026-65400) found within the Screen Share feature, which, if exploited, could grant an attacker full administrative control over a targeted Mac computer. The issue stems from an authentication bypass in the Screen Share mechanism, allowing unauthorized individuals to manipulate the keyboard and mouse inputs on a connected device.

Reports from tech security outlets like Ars Technica, as well as official advisories from the Netherlands National Cyber Security Centre (NCSC), have confirmed the severity of this flaw. The NCSC had issued a warning last week, shortly after details of the exploit became public. Investigations by cybersecurity firm Calif further detailed how the vulnerability operates. Their research, spurred by Apple's urgent out-of-band update, pinpointed that the security lapse was due to "insufficient state management during the authentication process." When Screen Share is active, macOS firewalls expose port 5900, making devices susceptible to unauthorized access through atypical authentication attempts.

Evidence suggests that this vulnerability has already been exploited in real-world scenarios. The NCSC noted instances where attackers gained root access to compromised systems, subsequently installing unauthorized software, such as Monero crypto miners. A researcher who initially identified the exploit reportedly found approximately 40,000 Mac devices with Screen Share enabled and accessible over the internet, indicating a broad potential attack surface. Apple's patch has been rolled out for macOS Tahoe, Sequoia, and Sonoma. All users of these macOS versions are strongly advised to perform the security update without delay to safeguard their systems against potential cyber threats.

This incident serves as a stark reminder of the continuous cat-and-mouse game between software developers and malicious actors. Users must remain vigilant about security updates and apply them promptly to protect their digital environments. The swift action by Apple and the collaborative efforts of cybersecurity researchers underscore the importance of a proactive approach to digital security. Ignoring these updates can leave systems vulnerable to significant breaches, potentially leading to data theft, system compromise, and other detrimental consequences. Always ensure your operating system and applications are up to date.

New Website Reveals If Your License Plate Was Tracked by Surveillance Cameras

Amidst increasing public concern over pervasive surveillance technologies, a new online tool called 'Have I Been Flocked?' has launched, empowering drivers to ascertain whether their license plate data has been accessed through Flock Safety's extensive network of automated license plate recognition (ALPR) cameras. This development comes as communities nationwide grapple with the privacy implications of such systems, leading to protests, contract cancellations, and calls for greater transparency.

New Online Tool Offers Glimpse into Widespread Surveillance

Launched on August 17, 2026, the website HaveIBeenFlocked.com offers a crucial service: allowing individuals to enter their license plate numbers to determine if they are present in publicly disclosed audit logs from Flock Safety's surveillance operations. The platform has already amassed a substantial database, containing nearly 242 million searches spanning over 4.6 million unique license plates. This initiative directly responds to the burgeoning debate surrounding privacy and accountability in the age of omnipresent digital oversight.

The creation of 'Have I Been Flocked?' is particularly timely, given recent revelations of potential abuses of ALPR technology. A comprehensive investigation by the Washington Post revealed that at least 50 law enforcement officers have faced charges or accusations of misusing license plate readers, including instances of stalking individuals without their knowledge or consent. Furthermore, reports from 404 Media have documented thousands of Flock searches conducted by local police at the behest of federal agencies, often for purposes that raise significant civil liberties concerns, such as immigration enforcement or informal requests.

While Flock Safety maintains that federal agencies like ICE do not have direct access to its system, the audit logs underscore how local departments can effectively act as intermediaries, sharing data with federal counterparts. Users of the 'Have I Been Flocked?' website should be aware that while a match indicates a query was made for their plate, it does not necessarily imply a formal investigation or that they were involved in criminal activity. The search results, which may include the querying agency, the individual who performed the search, and the stated reason, can be incomplete or redacted. It is also important to note that Flock's network extends beyond law enforcement to include private entities such as businesses, schools, and homeowner associations, all of whom can utilize the system.

The database for 'Have I Been Flocked?' is meticulously compiled from audit logs released by local governments through transparency portals or obtained via public records requests. Due to the decentralized nature of these data releases, the website's records may not be exhaustive, and there can be significant delays between when a search occurs and when it appears in the public database. Therefore, the absence of a result does not definitively guarantee that a license plate has never been searched. The platform also attempts to identify the operators by cross-referencing partial names found in audit logs with public police rosters, though these identifications are probabilistic and require independent verification.

For those who discover concerning entries, the project recommends submitting a public records request to the implicated agency and consulting with legal counsel if improper surveillance is suspected. Beyond individual plate lookups, the website offers broader insights, allowing visitors to analyze search patterns by agency and identify trends related to immigration enforcement, First Amendment activities, minor offenses, and instances where searches were conducted to 'develop probable cause.'

This pioneering effort by 'Have I Been Flocked?' represents a significant step towards demystifying the opaque world of mass surveillance, providing individuals with a tool to reclaim some measure of awareness and control over their personal data in an increasingly monitored society.

The proliferation of automated license plate readers (ALPRs) presents a classic dilemma between security and privacy. While proponents argue that these systems are indispensable tools for law enforcement, aiding in the recovery of stolen vehicles and the apprehension of suspects, the 'Have I Been Flocked?' website illuminates the darker side of this technology. It serves as a stark reminder that even seemingly innocuous data points, like a license plate, can contribute to a comprehensive digital footprint that, if unchecked, can lead to potential abuses and infringements on civil liberties. This initiative encourages citizens to engage with their local governments and demand greater transparency and oversight regarding the use of such powerful surveillance tools, fostering a more informed and empowered populace in an era of expanding digital scrutiny.

See More

German Regulators Mandate Apple to Neutralize Data Consent Prompts

Apple is facing a significant mandate from German authorities regarding its data collection consent mechanisms. The Federal Cartel Office has instructed the tech giant to overhaul the user interface and language of its data consent prompts on iPhones and iPads. This directive stems from allegations that Apple's existing pop-ups were designed to subtly discourage users from granting data access to third-party applications, while simultaneously promoting consent for its proprietary services. This move underscores the ongoing global scrutiny of major tech companies' data practices and their adherence to regulations aimed at fostering fair competition.

German Regulator Forces Apple to Redesign Data Consent Prompts by Early 2027

In a pivotal decision announced on August 17, 2026, Germany's Federal Cartel Office (Bundeskartellamt) has compelled Apple to modify its data tracking consent prompts. The regulator accused Apple of employing a biased design in its App Tracking Transparency (ATT) pop-ups, which allegedly steered users away from allowing third-party apps to access their data, contrasting with a more permissive approach for Apple's own 'Personalized Ads' prompts.

The preliminary assessment highlighted several elements contributing to this perceived steering effect: distinct symbols (such as a warning hand icon for third-party requests), varied terminology ('app tracking' versus 'personalized advertising'), potentially unclear descriptions of data usage, differing amounts of space allocated for explaining data usage benefits, and the presentation order of selection options.

Apple has been granted a four-month period to implement the necessary changes. These revisions are expected to remove any discouraging language and symbols from third-party app consent requests, adopting a more neutral design consistent with those used for Apple's own applications. Furthermore, the updated policy will permit third-party developers to integrate or link Apple's mandatory consent pop-ups with their own data collection prompts.

This ruling holds broad implications, as sources such as Reuters indicate that these changes will be applied across nearly all European Union countries. This action is a direct consequence of Apple being designated a 'gatekeeper' under the EU's Digital Markets Act (DMA) rules, which aim to ensure a level playing field in the digital market and prevent dominant platforms from unfairly favoring their own services.

This regulatory intervention represents a crucial step towards enhancing data privacy and fairness in the digital marketplace. It reaffirms the growing commitment of regulatory bodies to challenge the power of tech giants and ensure that users have genuinely informed choices about their personal data. The outcome will likely influence how other major technology companies design their data consent interfaces, promoting greater transparency and user control across the industry.

See More