
A macOS vulnerability patched by Apple last week is now being actively exploited in the wild, according to Dutch cybersecurity officials, who say attackers have already used it to gain root access on exposed Macs and install Monero miners. The flaw, tracked as CVE-2026-65400, affects Apple’s screen sharing feature and can allow an unauthenticated attacker to take over a system if the service is reachable from the Internet.
What Apple fixed in macOS
Apple addressed CVE-2026-65400 in updates released last week for macOS Tahoe, Sequoia, and Sonoma. The company rated the issue 7.1 out of 10 and said the bug “may” allow an attacker without credentials to gain access to a Mac. The wording is cautious, but the practical risk is clear: a flaw in the system’s screen sharing capability can let a remote party view the screen and control the keyboard and mouse on a machine that is powered on.
The vulnerability was publicly discussed at last week’s Black Hat security conference, where details became available shortly before the patch. According to the description, the issue stems from a problem in “state management,” the logic macOS uses to track prior events, user interactions, variables, and other system conditions. When that state tracking goes wrong, it can create an opening for an attacker to break into the service.
Active exploitation on exposed port 5900
The Netherlands National Cyber Security Centrum, or NCSC, said it has received reports showing active abuse of the flaw on multiple systems. In those cases, attackers targeted machines where port 5900 was accessible from the Internet.
The NCSC said that in all of the observed incidents, “root had been accessed on the affected system and a Monero crypto miner had been placed.” That detail matters because root access means the attacker had full control over the machine, not just limited user-level access. Once inside, the intruder can install software, alter security settings, and potentially move deeper into the network.
So far, the reported payload appears limited to cryptocurrency mining. But security officials warn that the same entry point could just as easily be used for credential theft, spyware, or other malicious activity if the vulnerability is left unpatched and exposed to the Internet.
Why screen sharing becomes risky
On Macs, enabling screen sharing can cause the firewall to open port 5900. That port is commonly associated with remote desktop access and, if reachable from outside the local network, can provide an attacker with a direct path to the vulnerable service.
In many environments, routers and dedicated firewalls block the port by default. Problems arise when users or administrators intentionally override those protections, or when screen sharing is enabled on a system that is not otherwise well protected. The attack described by the Dutch agency appears to depend on exactly that kind of exposure.
Security professionals generally recommend that Mac users avoid leaving screen sharing permanently enabled. A safer setup is to keep the feature off until it is actually needed, then shut it down immediately after the session ends. When remote access is required, experts often prefer methods such as VPN connections or SSH tunneling because they add a layer of authentication and reduce the chance that port 5900 is exposed directly to the Internet.
What Mac users should do now
For most users, the most important step is simple: install Apple’s security update as soon as possible. If the patch has already been released for your version of macOS, applying it closes the known vulnerability and reduces the chance that an exposed system can be taken over.
Users who rely on screen sharing should also check whether the feature is active and whether the machine is reachable from outside their network. On macOS, screen sharing can be managed through System Settings > General > Sharing, where the Screen Sharing switch can be turned on or off.
In practical terms, the advice breaks down into a few priorities:
- Install the latest macOS security update for Tahoe, Sequoia, or Sonoma.
- Disable Screen Sharing unless you need it for a specific task.
- Confirm that port 5900 is not open to the Internet.
- Use a VPN or SSH tunneling rather than direct exposure when remote access is necessary.
- Turn Screen Sharing off again once the session is finished.
Why the incident matters beyond cryptocurrency mining
The current wave of abuse appears to involve Monero miners, which are designed to quietly consume a computer’s CPU or GPU resources to generate cryptocurrency for the attacker. That kind of payload is disruptive, but it is not the worst-case scenario.
What makes CVE-2026-65400 especially concerning is the level of access it can provide. Root control on a Mac can give an intruder the ability to modify system files, disable protections, create persistent access, and deploy additional malware. Even if today’s attackers are only interested in mining, the same vulnerability could be repurposed for more aggressive campaigns later.
That is why the NCSC warning is significant. Active exploitation means this is no longer a theoretical issue for researchers or a patch to schedule for later. It is a live threat, and any Internet-exposed Mac with Screen Sharing enabled is a potential target.
A reminder that exposure matters as much as the bug
This case also shows how a software flaw and a network configuration can combine to create serious risk. A vulnerability in a service does not become dangerous in every setting, but once that service is reachable from the Internet, the odds change quickly.
For organizations, that means patching should go hand in hand with exposure reviews. Administrators should verify which Macs have screen sharing enabled, whether any firewall rules or router settings expose port 5900, and whether remote access workflows can be redesigned to keep the port closed. For individual users, the same logic applies: if you are not actively using the feature, leaving it on creates unnecessary risk.
Apple’s patch addresses the flaw itself, but the recent exploitation reports are a reminder that updates alone are not the whole defense. Secure configuration, limited exposure, and prompt maintenance all matter when attackers move quickly on newly disclosed bugs.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: August 15, 2026 at 1:52 am
0 views
