Critical macOS Vulnerability Giving Attackers Full Control of Macs Under Active Exploitation

August 15, 2026 at 12:25 am
1 min read

A high-severity macOS vulnerability tracked as CVE-2026-65400 is currently under active exploitation, allowing remote hackers to bypass passwords and gain root access to affected machines. The Netherlands National Cyber Security Centrum (NCSC) warned that attackers are leveraging the flaw to install Monero crypto miners on exposed systems.

Understanding the Screen-Sharing Flaw

The security loophole, which carries a severity rating of 7.1 out of 10, originates from a state management bug within the built-in macOS screen-sharing feature. First brought to light at the Black Hat security conference and subsequently patched by Apple for macOS Tahoe, Sequoia, and Sonoma, the bug permits remote actors to view screens and manipulate keyboards and mice without valid credentials.

How the Attacks Happen

According to the NCSC, active exploitation has been observed primarily on systems where port 5900 is directly accessible from the internet. When screen sharing is enabled, the macOS firewall automatically opens this specific port. While current attacks are strictly focused on deploying resource-heavy Monero miners, cybersecurity experts warn of a broader threat involving credential theft and malware deployment.

Recommended Safety Measures

Security practitioners strongly advise Mac users to immediately install the latest security updates provided by Apple. Furthermore, users should keep port 5900 closed, utilize a VPN or SSH tunneling for remote connections, and ensure that the screen-sharing feature is toggled off in System Settings when not actively in use.