Technology
Ars Technica - All content

Vulnerability giving attackers full control of Macs is under active exploitation

Source Entity

Dan Goodin

August 16, 2026
Vulnerability giving attackers full control of Macs is under active exploitation

A high-severity macOS vulnerability (CVE-2026-65400) is currently being exploited to gain unauthorized root access and install crypto-mining malware. Apple has released patches for recent macOS versions, and users are urged to disable internet-accessible screen sharing immediately.

Critical macOS Security Alert: CVE-2026-65400

The Nature of the Threat

A significant security vulnerability, officially tracked as CVE-2026-65400, has been identified within the screen-sharing infrastructure of Apple’s macOS operating system. This flaw, which carries a severity rating of 7.1 out of 10, allows unauthorized remote actors to bypass authentication protocols. By exploiting the inherent screen-sharing capabilities, attackers can gain full control over a target machine, effectively bypassing password requirements that would otherwise secure the system.

Active Exploitation and Real-World Impact

The Netherlands National Cyber Security Centrum (NCSC) has confirmed that this is not merely a theoretical risk. Reports indicate active abuse of the vulnerability, specifically targeting systems where port 5900—the standard port for Virtual Network Computing (VNC) and screen sharing—is left exposed to the public internet. The NCSC observed multiple instances where attackers successfully escalated privileges to 'root' access, granting them complete administrative control over the affected hardware.

The Rise of Crypto-Jacking

In the documented cases of exploitation, the primary objective of the attackers appears to be the deployment of Monero crypto-miners. By hijacking the victim's CPU resources, attackers can generate digital currency at the expense of the user. This 'crypto-jacking' trend highlights a shift in cyber-criminal tactics: rather than focusing solely on data theft or ransomware, attackers are increasingly utilizing compromised systems as silent, distributed computing nodes to generate illicit profit.

Remediation and Patching

Apple has responded to this threat by issuing security patches for macOS Tahoe, Sequoia, and Sonoma. These updates are essential for closing the specific bug within the screen-sharing framework. It is imperative that users verify their system version and apply these updates immediately. Beyond patching, the NCSC strongly advises against exposing port 5900 to the public internet, as this serves as the primary vector for these remote attacks.

Broader Cybersecurity Implications

This incident serves as a stark reminder of the risks associated with remote administration tools. When services like screen sharing are left open to the open web, they become beacons for automated scanning tools used by malicious actors. As remote work and remote IT support remain common, the balance between accessibility and security becomes increasingly precarious. Users must adopt a 'least privilege' mindset, ensuring that only necessary ports are open and that all software is kept strictly up to date.

Conclusion

While the release of the patch is a critical step forward, the active exploitation of CVE-2026-65400 underscores the necessity of proactive defense. Mac users should audit their system settings to ensure screen sharing is either disabled or restricted to trusted local networks. By combining timely software updates with secure network configurations, users can mitigate the risk posed by this high-severity vulnerability and protect their systems from unauthorized access and malicious resource exploitation.

Verification Required?

Read the full report from the primary source

Go to Ars Technica - All content