2 min read

Mac Screen Sharing flaw is under active attack

A macOS Screen Sharing flaw is under active attack. Apple patched Sonoma, Sequoia, and Tahoe after attackers gained root access and installed Monero miners.

Image: 9to5mac

Source: Itzine

A vulnerability in macOS Screen Sharing is being actively exploited against Macs with TCP port 5900 exposed to the internet. Attackers have gained root access and installed Monero cryptocurrency miners, according to Itzine, citing the Netherlands National Cyber Security Centrum (NCSC).

Apple patched the flaw, tracked as CVE-2026-65400, in macOS Sonoma 14.8.9, Sequoia 15.7.9, and Tahoe 26.6.1. The vulnerability has a 7.1 out of 10 severity rating. 9to5Mac reports that Apple initially described the releases only as containing “important security fixes,” before expanding the security notes.

Apple’s description says an attacker on the network may be able to authenticate to Screen Sharing without valid credentials. The company attributed the fix to improved state management, addressing a flaw in how the system tracks previous events, user actions, variables, and other state information.

Screen Sharing can expose the logged-in Mac’s display and allow remote control of its keyboard and mouse. In practice, that could give an attacker access to applications, files, credentials, and other capabilities available to someone using the computer directly.

Recommended reading

France’s tax breach exposes data on 678,000 people

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet. In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

Netherlands National Cyber Security Centrum

Apple previously said CVE-2026-65400 “may” allow an attacker without credentials to access a Mac, and did not explain the cautious wording. The NCSC’s report now confirms exploitation on multiple internet-accessible systems.

Mac owners who have not installed the Sonoma, Sequoia, or Tahoe updates should do so immediately. Screen Sharing can also be disabled in System Settings > General > Sharing; it should be turned off when a remote session is no longer needed.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

/ Keep reading