“No user interaction is required. The only prerequisite is that Screen Sharing is enabled on the target.”
The screensharingd frame-length check returns the stale success status from the previous read when a frame is too large, so an oversized length value skips authentication entirely and hands over arbitrary file read and write as root. It is a bug that would have been caught by checking one return value. Apple fixed it in macOS 26.6 on July 27, which means every Mac with remote management enabled and a deferred update is still open. The writeup carries a disclaimer that AI coding agents produced it autonomously, so treat the prose with more suspicion than the bug.