A remote desktop feature built into every modern Mac has become an open door for hackers, and Dutch cybersecurity officials say the break-in is already happening. Security researchers and government agencies are now warning users about an actively exploited macOS screen sharing vulnerability that lets attackers take control of a computer without ever needing a password, then quietly install cryptocurrency mining software on the machine.
Key takeaways
- The flaw, tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10 and lets attackers execute code remotely without valid credentials.
- The Netherlands’ National Cyber Security Centrum (NCSC) confirmed active exploitation on systems where port 5900 was reachable from the internet.
- Attackers who exploited the bug gained root access and installed Monero crypto miners on affected Macs.
- Apple patched the issue last week in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
- Users can reduce risk by disabling Screen Sharing when it’s not in use and installing the latest security update.
High-Severity macOS Vulnerability Allows Remote Code Execution
CVE-2026-65400 is a bug that lets a remote attacker run malicious code on a Mac without needing a username or password. Apple’s built-in Screen Sharing feature, which uses the VNC protocol to let one computer view and control another over a network, is at the center of the problem.
Nature and Source of the Vulnerability
The root cause traces back to how macOS handles “state management” inside the screen sharing system — the internal bookkeeping that tracks prior events, user interactions, and system variables. A flaw in that logic allows an intruder to sidestep proper credential checks entirely. In practical terms, someone connecting to a vulnerable Mac’s screen sharing port doesn’t need to prove who they are before gaining access.
Severity Rating and Technical Details
Apple and security researchers rate the flaw at 7.1 out of 10, a score that lands it in high-severity territory without reaching the maximum critical tier. Details of the bug first became public at last week’s Black Hat security conference, and Apple’s own advisory described the issue cautiously, saying the vulnerability “may” allow an attacker without credentials to access a Mac. That kind of hedged language is fairly typical across the tech industry when companies disclose security flaws, even when exploitation is already confirmed in the wild.
Active Exploitation Confirmed by Dutch National Cyber Security Centrum
The NCSC says it has already received reports of real-world attacks exploiting this macOS screen sharing vulnerability, not just theoretical risk. In an advisory update, the agency stated it had received a notification indicating active abuse of the flaw on multiple systems where port 5900 was accessible from the internet.
Conditions for Exploitation
Port 5900 is the network channel that VNC-based screen sharing uses to communicate. When a Mac user turns Screen Sharing on, the built-in macOS firewall automatically opens that port. Most home routers and dedicated firewalls block port 5900 by default, but if a network has been configured to allow it through — intentionally or otherwise — the machine becomes reachable from anywhere on the internet. That exposure is exactly the condition the NCSC says attackers have been exploiting.
Observed Impact on Affected Macs
According to the NCSC’s advisory, every confirmed case followed the same pattern: attackers gained root access to the system, then placed a Monero crypto miner on the machine. Monero mining malware quietly hijacks a computer’s processing power to generate cryptocurrency for the attacker, often without any obvious symptoms beyond a sluggish machine and a spike in electricity use. So far, there’s no indication that attackers have used the exploit to deploy anything more damaging than a crypto miner — but the same root-level access could theoretically be repurposed to steal credentials or install more harmful malware.
Apple Issues Patch and Security Recommendations
Apple has already shipped a fix, which is the single most effective way to close off this attack path. The company released updates last week that improve the state management mechanisms behind Screen Sharing, enforcing proper credential validation and blocking the rogue authentication attempts that made the exploit possible.
Patch Release Details
The fix landed in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Anyone running an older build of these three macOS releases remains exposed to the vulnerability until they update.
User Security Best Practices
Beyond installing the patch, security practitioners recommend keeping Screen Sharing off unless it’s actively needed, and switching it off again once a session ends. The toggle sits in System Settings, under General, then Sharing, where users can switch the Screen Sharing option on or off. For those who need remote access, connecting through a VPN or SSH tunnel instead of exposing port 5900 directly to the internet is considered safer, though that approach requires technical steps that fall outside what most everyday users are equipped to configure. That gap is part of why an addressable macOS screen sharing vulnerability like this one still manages to catch so many systems off guard: the safest workaround demands more networking know-how than the average Mac owner has on hand.
Why This Still Matters for Mac Users
This case is a reminder that convenience features carry hidden exposure. Screen Sharing is meant to make remote troubleshooting and file access easier, but leaving it switched on by default — especially on a network where port 5900 slips past a router’s firewall — turns a helpful tool into an open invitation. The NCSC hasn’t disclosed how many systems have been hit, when the attacks began, or whether the exploitation extends beyond cryptomining, leaving open the possibility that some compromised Macs are dealing with more than just a hidden miner running in the background.
FAQ
What is the nature of the macOS vulnerability CVE-2026-65400?
It is a flaw in macOS screen sharing state management that allows remote attackers to execute malicious code without credentials.
How are attackers exploiting this vulnerability?
Attackers exploit the vulnerability when port 5900 is exposed to the internet and screen sharing is enabled, gaining root access and installing Monero miners.
Which macOS versions have a patch for this vulnerability?
Apple released patches last week for macOS Tahoe, Sequoia, and Sonoma to fix the vulnerability.
What security steps can users take to protect themselves?
Users should disable screen sharing when not in use, close port 5900, and install the latest security updates.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.





Be the first to comment