Vulnerability giving attackers full control of Macs is under active exploitation

by | Aug 28, 2026 | Technology

Vulnerability giving attackers full control of Macs is under active exploitation

Dutch cybersecurity authorities reported this week that a high-severity macOS vulnerability is being actively exploited across multiple systems. The Netherlands National Cyber Security Centrum indicated that attackers have successfully gained root-level access on affected machines and installed Monero cryptocurrency miners on systems where port 5900 was accessible from the Internet.

The vulnerability, designated CVE-2026-65400, affects macOS Tahoe, Sequoia, and Sonoma. Apple released patches for the issue last week. The flaw exists in the macOS screen-sharing feature, which permits remote users to view displays and control keyboards and mice on active machines. The underlying problem involves a state management defect that improperly tracks system events, user interactions, and variables.

According to Apple, the vulnerability potentially permits attackers without valid credentials to access Mac systems. Security firm Bynario initially reported the flaw, which gained public attention following its presentation at the Black Hat security conference last week. The vulnerability carries a severity rating of 7.1 out of 10.

Exploits typically succeed when port 5900 remains open to internet traffic. The macOS firewall automatically opens this port when screen sharing is enabled. While routers and firewalls generally block the port by default, security researchers recommend users employ alternative connection methods such as virtual private networks or SSH tunneling. For most users, security practitioners advise disabling screen sharing entirely and enabling it only when necessary, then promptly disabling it afterward. Users can manage screen sharing through System Settings > General > Sharing.

Currently, observed exploitation has focused on installing cryptocurrency miners. Security experts warn that attackers could potentially leverage the vulnerability to deploy credential-stealing malware or conduct other malicious activities. Installing the recently released security update remains critical for affected users.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI