
Dutch cybersecurity officials have alerted the public to ongoing exploitation of a high-severity macOS vulnerability that enables attackers to execute malicious code on affected machines. The Netherlands National Cyber Security Centrum reported earlier this week that the flaw has been actively abused on multiple systems where port 5900 was accessible from the internet. In each documented case, attackers successfully obtained root access and installed Monero cryptocurrency miners.
The vulnerability, designated CVE-2026-65400 with a severity score of 7.1 out of 10, stems from a flaw in the macOS screen-sharing function. This feature permits remote parties to view displays and control keyboards and mice on active machines. The underlying issue lies in improper state management, which tracks system events, user interactions, variables, and other operational states. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week in response to the flaw.
Information about CVE-2026-65400 became public at a major security conference last week. Apple’s advisory indicated the vulnerability “may” permit unauthenticated attackers to access affected Mac systems, though the company’s cautious language is typical among technology vendors disclosing security flaws. Security researchers at Bynario initially reported the vulnerability to Apple.
Exploitation occurs when port 5900 remains exposed to internet access, which opens automatically when screen sharing is activated. While standard routers and firewalls typically block this port unless configured otherwise, cybersecurity professionals recommend Mac users maintain port closure and utilize alternative connection methods such as virtual private networks or SSH tunneling. Currently observed attacks have been limited to cryptocurrency miner installation, though experts warn attackers could potentially deploy credential-stealing malware or conduct other harmful activities.
Users are advised to disable screen sharing when not in use, enable it only when necessary, and disable it immediately after completing sessions. Screen sharing settings can be modified through System Settings, General, and Sharing menus. Installing the recently released security update remains essential for all affected Mac users.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI