Vulnerability giving attackers full control of Macs is under active exploitation

| Source: Ars Technica AI

Tags: CVE-2026-65400, macOS, Apple, cybersecurity, screen-sharing, Black-Hat

A patched macOS screen-sharing flaw (CVE-2026-65400) is under active exploitation — attackers gain unauthenticated root access via port 5900 and install Monero miners on exposed systems, Dutch NCSC confirmed.

Details

Dutch cybersecurity agency NCSC confirmed active exploitation of CVE-2026-65400, a severity 7.1/10 macOS vulnerability in the screen-sharing feature. When port 5900 (opened automatically when screen sharing is enabled) is internet-accessible, attackers bypass authentication entirely due to a state management bug. Apple released patches last week for macOS Tahoe, Sequoia, and Sonoma after technical details went public at Black Hat. Confirmed attacks have installed Monero cryptocurrency miners after gaining root access. The NCSC received multiple incident notifications, with root compromise confirmed across several systems. The vulnerability requires no credentials — the attacker only needs port 5900 reachable from the internet. For enterprises with Mac-heavy environments: patch immediately, disable screen sharing where not required, and if screen sharing is needed, route it through VPN or SSH tunneling. Exposing port 5900 directly is the attack surface. Current exploitation appears limited to Monero mining, but the same root access could deploy credential stealers or persistent malware.