Vulnerability giving attackers full control of Macs is under active exploitation
Key Points:
- Dutch cybersecurity officials have warned of active exploitation of a high-severity macOS vulnerability (CVE-2026-65400) that allows attackers to execute malicious code by exploiting the screen sharing feature.
- The vulnerability, patched by Apple last week for macOS Tahoe, Sequoia, and Sonoma, stems from a bug in state management within the screen sharing capability, enabling remote control of the keyboard and mouse without credentials.
- Exploits have been observed on systems with port 5900 exposed to the Internet, leading to root access and installation of Monero cryptocurrency miners; users are advised to block this port, use VPNs or SSH tunneling, and disable screen sharing when not in use.
- Apple’s patch and disabling screen sharing when not needed are critical security measures, as the vulnerability could potentially be used for more harmful attacks beyond cryptocurrency mining, such as credential theft or malware installation.
- The vulnerability details were publicly disclosed at the Black Hat security conference, with a demonstration video available, highlighting the urgent need for users to update their systems and secure screen sharing settings.