Apple has released a trio of macOS updates—macOS 26.6.1 Tahoe, macOS 15.7.9 Sequoia, and macOS 14.8.9 Sonoma—to address a vulnerability in Screen Sharing. The release notes say, “An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.”
There’s no indication that this bug has been exploited in the wild. In fact, Apple’s wording suggests to me that Screen Sharing is vulnerable to unauthenticated connections over the local network, not the Internet. Plus, Screen Sharing is turned off by default, so it seems likely that only Macs with it explicitly enabled would be vulnerable. You can check your status in System Settings > General > Sharing > Screen Sharing.
I don’t understand why these updates are so large. Despite the Screen Sharing app itself being less than 6 MB, the updates range from 1.5 to 2.1 GB. Sure, there are probably some under-the-hood frameworks involved, but gigabytes worth of files needed to change for this fix?
Regardless, the possibility of an unauthenticated user being able to observe or control another Mac via Screen Sharing is sufficiently concerning that I recommend everyone update as soon as is convenient.