Vulnerability giving attackers full control of Macs is under active exploitation

by | Aug 18, 2026 | Technology

Vulnerability giving attackers full control of Macs is under active exploitation

Dutch cybersecurity authorities reported this week that a critical macOS flaw is currently being weaponized in active attacks across multiple systems. The Netherlands National Cyber Security Centrum stated it had received notification of ongoing abuse of the vulnerability on systems where port 5900 was exposed to internet access. In each documented case, attackers achieved root-level access and deployed Monero cryptocurrency mining software on the affected machines.

Apple released patches for the vulnerability, designated CVE-2026-65400, last week for macOS Tahoe, Sequoia, and Sonoma versions. The flaw, rated with a severity score of 7.1 out of 10, exists within the macOS screen sharing functionality that permits remote users to view displays and operate keyboards and mice on active systems. The underlying defect involves improper state management—the tracking mechanism responsible for monitoring preceding events, user interactions, variables, and other system conditions.

The vulnerability gained public attention following its presentation at last week’s Black Hat security conference. Apple’s advisory indicated that the flaw potentially allows unauthenticated attackers to obtain access to Mac systems, though the company employed cautious phrasing in its disclosure. Security researcher Bynario is credited with identifying and reporting the vulnerability.

Exploitation occurs when port 5900 remains accessible from the internet, a condition that arises when screen sharing is enabled, as the macOS firewall automatically opens this port to facilitate the feature. While standard routers and firewalls typically block the port, users can override these protections through configuration changes. Industry experts recommend keeping the port closed and instead utilizing alternative connection methods such as virtual private networks or SSH tunneling, though these approaches may exceed the technical capabilities of typical users.

Current observations show attackers are limiting their use of the vulnerability to cryptocurrency mining operations that hijack system resources for mathematical calculations generating cryptocurrency. However, security professionals warn of heightened risk if the vulnerability is exploited to distribute credential-stealing malware or conduct more severe attacks. Users are advised to disable screen sharing when not in use, enable it only as needed, and promptly install the latest security updates.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI