
The Netherlands National Cyber Security Centrum has warned that a high-severity macOS vulnerability is being actively exploited in the wild. The agency reported receiving notifications of the vulnerability being abused on multiple systems where port 5900 was accessible from the Internet. In each observed case, attackers gained root-level access to affected machines and installed Monero cryptocurrency miners.
The vulnerability, identified as CVE-2026-65400, affects macOS Tahoe, Sequoia, and Sonoma versions. Apple released patches for the flaw last week. The issue stems from a bug in the macOS screen-sharing feature, which enables remote users to view screens and control keyboards and mice on active machines. The underlying problem involves a state management flaw that tracks preceding events, user interactions, variables, and other system states. The vulnerability carries a severity rating of 7.1 out of 10.
The flaw became publicly disclosed at a security conference last week, with video demonstrations of the exploit circulating. Apple stated the vulnerability may allow unauthenticated attackers to access Macs, though the company used cautious language in its disclosure. Security researchers at Bynario initially reported the vulnerability to Apple. The exploitation occurs when port 5900 is exposed to the Internet; this port opens automatically when screen sharing is enabled on macOS. While routers and firewalls typically block this port by default, custom configurations can leave it open.
Current exploits have only deployed cryptocurrency miners, which use compromised computer resources for mathematical operations generating cryptocurrency for attackers. However, security experts warn that the vulnerability could be leveraged for more serious purposes, such as installing credential-stealing malware or deploying other malicious software.
Security professionals recommend users disable screen sharing when not in use, utilize VPN or SSH tunneling for necessary remote access, and install the latest security updates. Users can manage screen sharing through System Settings under General > Sharing.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI