Bottom line: Apple's 20-year-old macOS 10.5 (Leopard) screen sharing vulnerability remains unaddressed, leaving users vulnerable to potential man-in-the-middle attacks.
What's happening: Researchers at MIT published a 2020 paper detailing the vulnerability in Apple's screen sharing protocol, which relies on the unencrypted VNC (Virtual Network Computing) protocol, using TCP port 5900. This vulnerability was first introduced in macOS 10.5 (Leopard), released in 2007.
What to do: Security teams should prioritize patching macOS 10.5 (Leopard) and ensuring employees use secure alternatives for screen sharing, such as Webex or Zoom, with two-factor authentication enabled.