
Dutch cybersecurity officials have reported that a critical macOS vulnerability is being actively exploited in the wild. The Netherlands National Cyber Security Centrum disclosed that multiple systems with internet-exposed port 5900 have been compromised, with attackers gaining root access and deploying Monero cryptocurrency miners on each affected device.
The vulnerability, designated CVE-2026-65400, affects the macOS screen-sharing feature and carries a severity rating of 7.1 out of 10. It stems from a flaw in state management within the screen-sharing capability, which normally allows remote users to view displays and control input devices. Apple released patches last week for macOS Tahoe, Sequoia, and Sonoma versions. Security researchers at Bynario initially discovered and reported the flaw, with technical details emerging at the Black Hat security conference last week.
The vulnerability becomes exploitable when port 5900 is accessible from the internet. The macOS firewall automatically opens this port when screen-sharing functionality is enabled. While most routers and firewalls block this port by default, users who reconfigure their network settings to expose it face significant risk. Security experts recommend that Mac users maintain screen-sharing in a disabled state, activate it only when necessary, and promptly disable it after use.
Current exploitation activity shows attackers using the vulnerability exclusively to install cryptocurrency miners, which consume system resources to generate digital currency for the attackers. However, security officials warn that the vulnerability could be weaponized for more damaging purposes, such as deploying credential-stealing malware or other malicious software. Users are advised to install the latest security updates immediately and adjust screen-sharing settings through System Settings, with alternative secure connection methods such as VPN or SSH tunneling recommended for users who require remote access functionality.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI