Public VNC access is temporarily disabled on remote access builds and RDE sessions

Incident Report for Bitrise

Identified

A macOS Screen Sharing (VNC) vulnerability, CVE-2026-43760, has been announced. To protect your machines, we’ve disabled internet-facing access to VNC. SSH is unaffected and remains fully available.

We have no evidence that any customer machine was accessed as a result of this vulnerability. This is a proactive measure to reduce exposure.

You can connect to the VNC server by tunnelling it over SSH:

ssh -L 5900:localhost:5900 $SSH_ADDRESS

Then connect to `localhost:5900` with a VNC client.
Posted Jul 30, 2026 - 15:40 UTC
This incident affects: ⚙️ Builds (CI).