Vulnerability giving attackers full control of Macs is under active exploitation

by | Aug 21, 2026 | Technology

Vulnerability giving attackers full control of Macs is under active exploitation

Dutch cybersecurity officials have alerted the public that a high-severity vulnerability in macOS is currently being exploited in active attacks. The Netherlands National Cyber Security Centrum reported earlier this week that the flaw has been observed on multiple systems with port 5900 exposed to the internet, with attackers successfully obtaining root-level access and deploying Monero cryptocurrency miners on compromised machines.

The vulnerability, identified as CVE-2026-65400, affects the macOS screen sharing functionality and carries a severity rating of 7.1 out of 10. The flaw stems from improper state management in the screen sharing system, which typically allows users to view and control a remote Mac’s display, keyboard, and mouse. Apple released patches last week addressing the vulnerability across macOS Tahoe, Sequoia, and Sonoma versions. Security researchers from Bynario first discovered and reported the vulnerability to Apple.

Detailed information about the vulnerability was made public at the Black Hat security conference last week, including a video demonstration of the exploit. The vulnerability can be exploited when port 5900, which is opened by the macOS firewall when screen sharing is activated, is accessible from the internet. Security experts note that while home routers and firewalls typically block this port by default, custom configurations may expose it.

Current observations indicate attackers are using the vulnerability primarily to install cryptocurrency miners that consume system resources to generate Monero for the threat actors. However, security analysts warn that the vulnerability could potentially be leveraged for more damaging purposes, such as stealing user credentials or deploying other malware. Users can mitigate risk by installing the recent security update, disabling screen sharing except when actively in use, and keeping port 5900 closed. Alternative secure connection methods like VPNs or SSH tunneling are recommended when remote access is necessary.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI