Vulnerability giving attackers full control of Macs is under active exploitation

← Back to the feed

Vulnerability giving attackers full control of Macs is under active exploitation

Ars Technica · 3 hours ago

Dutch cyber-security officials say attackers are actively exploiting a high-severity macOS flaw that can let unauthenticated users gain control of affected Macs. The issue is particularly serious where Screen Sharing is enabled and port 5900 is exposed to the internet, as attackers have already obtained root access and installed cryptocurrency-mining software.

Apple patched CVE-2026-65400 last week for macOS Tahoe, Sequoia and Sonoma; it has a severity score of 7.1 out of 10 and stems from faulty Screen Sharing state management. Reported attacks have installed Monero miners so far, but the same access could potentially be used for credential theft or other malware; users are advised to install updates and disable Screen Sharing when not needed.

  • Mac Screen Sharing flaw is being actively exploited.
  • Exposed port 5900 has enabled root-level access.
  • Update macOS and disable unused Screen Sharing.

Cybersecurity Technology

Read the full article at the source →