The short version
- A critical vulnerability in macOS screen-sharing features is being actively exploited by remote attackers to gain full control of affected systems.
- The Netherlands National Cyber Security Centrum reports that compromised machines have had root access granted and Monero cryptocurrency miners installed.
- Apple has released patches for recent macOS versions, but users must ensure port 5900 is not exposed to the internet to prevent unauthorized entry.
A significant security breach affecting Apple computers is currently underway, with attackers actively exploiting a high-severity flaw in the macOS operating system. The vulnerability, identified as CVE-2026-65400, allows remote intruders to execute malicious code and gain complete control over infected machines without requiring user passwords or credentials. This development marks a serious escalation for Mac users, who have historically relied on the platform’s robust security architecture, though this incident highlights specific weaknesses in how screen-sharing services are managed.
The Netherlands National Cyber Security Centrum (NCSC) issued a warning earlier this week regarding the active abuse of this defect. Officials stated that they had received notifications indicating that multiple systems were compromised when port 5900 was accessible from the internet. In every confirmed case reported by the Dutch agency, attackers successfully accessed root privileges on the affected hardware. Once inside, the intruders installed Monero cryptocurrency miners, which silently harness the computer’s processing power to generate digital currency for the perpetrators.
The underlying cause of the breach is a bug within the state management system of macOS screen sharing. This component is responsible for tracking preceding events, user interactions, variables, and other system states. The flaw allows a remote party to view the screen and control the keyboard and mouse while the machine is powered on. Although the vulnerability carries a severity rating of 7.1 out of 10, its impact is severe because it bypasses standard authentication mechanisms entirely.
Apple addressed the issue by releasing a patch last week for macOS Tahoe, Sequoia, and Sonoma. The company acknowledged that the flaw may allow an attacker without credentials to gain access to a Mac. Security analysts note that Apple’s use of hedging language is common in vulnerability disclosures, but the practical reality observed by cybersecurity agencies confirms that full system compromise is possible. Details regarding CVE-2026-65400 were made public during last week’s Black Hat security conference, bringing attention to the active exploitation.
The attack vector relies on port 5900 being open to the internet. When users enable screen sharing, the macOS firewall automatically opens this port to facilitate connections. While routers and dedicated firewalls typically block such traffic unless specifically configured otherwise, many home networks may not have these protections in place. Security experts advise that Mac users should keep this port closed even when using screen sharing features, instead opting for more secure connection methods such as virtual private networks or SSH tunneling.
Implementing these alternative security measures often requires technical knowledge that is beyond the capabilities of average consumers. Consequently, the safest practice recommended by practitioners is to disable screen sharing entirely unless it is immediately needed. Users can toggle this feature on or off through System Settings under General and Sharing. Turning off the feature after a session ends significantly reduces the window of opportunity for attackers.
Currently, there is no evidence that exploits are being used to install malware beyond cryptocurrency miners. However, security professionals warn that the risk extends far beyond resource theft. Attackers could potentially leverage this vulnerability to install more dangerous software designed to steal sensitive credentials, capture personal data, or perform other nefarious activities. The ability to gain root access means an intruder has unrestricted control over the system.
Installing the latest security update is essential for all users running affected versions of macOS. Given that the vulnerability is under active exploitation, delaying updates leaves systems vulnerable to immediate compromise. Organizations and individuals should verify that their devices are patched and review firewall settings to ensure that unnecessary ports remain closed. This incident serves as a reminder that even minor configuration oversights can lead to severe security consequences.
The broader implication of this breach is the increasing sophistication of attacks targeting consumer electronics. As remote work and digital collaboration tools become more prevalent, features like screen sharing are used more frequently, expanding the attack surface for malicious actors. Cybersecurity agencies continue to monitor the situation for any changes in attacker behavior or new variants of the exploit.
Users who suspect their Macs have been compromised should check for unusual system performance issues, such as unexpected fan noise or high CPU usage, which are common signs of cryptocurrency mining. If such symptoms are present, running a full security scan and changing all associated passwords is advisable. Staying informed about security updates and maintaining strict control over network access remains the best defense against these types of intrusions.
Sources behind this briefing
Go to the original reporting
- Ars Technica↗Vulnerability giving attackers full control of Macs is under active exploitation