
Attackers are actively exploiting a critical flaw in macOS Screen Sharing to remotely take control of exposed Macs and install a Monero miner. Apple patched the issue on August 6, 2026, but unpatched systems remain vulnerable.
Confirmed attacks in the Netherlands
The Dutch National Cyber Security Centre (NCSC-NL) reported on August 12, 2026, that the CVE-2026-65400 vulnerability — an authentication error in macOS Screen Sharing — is being exploited in the wild. In all observed cases, attackers gained root access and deployed Monero mining software on machines where port 5900 was accessible from the internet.
This port, used by default by the VNC protocol integrated into macOS, is automatically exposed by the system firewall when Screen Sharing is enabled. The flaw allows an attacker on the same network to authenticate without valid credentials and then take full control of the machine.
Urgent patch, severity reassessed
Apple released updates on August 6, 2026, for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, fixing the flaw with "improved state management" during authentication. Initially rated 7.1 on the CVSS scale, the vulnerability was reclassified to 9.8 (critical) by CISA on August 14, which now deems it "automatable" — an attacker can compromise a Mac without prior privileges or user interaction.
Researcher Alfredo Pesoli, credited with the discovery, explained that the flaw stems from a desynchronization issue in the authentication process of the screensharingd daemon. Another researcher, @osxreverser, revealed having identified a similar vulnerability (not referenced under CVE-2026-65400) that allows bypassing authentication without knowing the password, simply by knowing the target’s IP address.
RecommendedWindows zero-day grants SYSTEM rights even on patched PCs
What to do now
- Update macOS to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 via System Settings > General > Software Update.
- Disable Screen Sharing if unused (System Settings > General > Sharing).
- Verify that port 5900 is not exposed to the internet, especially by using a VPN if Screen Sharing is necessary.
- Avoid exposing this service directly to the internet, even behind a password.
CISA has not yet added CVE-2026-65400 to its Known Exploited Vulnerabilities catalog, but its high score and NCSC-NL reports confirm an immediate risk. Attacks currently focus on cryptocurrency mining, but root access opens the door to data theft or lateral movement within networks.
“Send one or two packets in the right order, and the target Mac lets you in. It works every time, on every unpatched machine with Screen Sharing enabled.” — @osxreverser, security researcherTranslated from French
This case highlights that Screen Sharing services, even password-protected, remain prime targets. With AI assistance, the time between discovering a flaw and exploiting it is shrinking, as demonstrated by the company Calif, which generated a working exploit in four hours.
Sources
Engadget — Apple Screen Sharing bug exploited in the wild
MacRumors — macOS Screen Sharing Flaw Is Being Exploited in the Wild
Tom's Hardware — Critical macOS Screen Sharing flaw gives attackers remote root access
The Hacker News — Apple macOS Screen Sharing Flaw Exploited to Install Monero Miner
9to5Mac — A serious Mac screen sharing vulnerability is being actively exploited




Comments 0
Sign in to join the discussion.
Be the first to comment.