Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
The Netherlands National Cyber Security Centrum has warned that a critical macOS vulnerability, tracked as CVE-2026-65400, is being actively exploited by attackers. The vulnerability allows malicious code to be executed on a compromised system. According to the NCSC, the abuse of this vulnerability has been observed on multiple systems where port 5900 is accessible from the Internet.
In these cases, the root account was accessed, and a Monero crypto miner was installed. Apple released a patch for macOS Tahoe, Sequoia, and Sonoma to address this issue, which has a severity rating of 7.1 out of 10. This vulnerability arises from a flaw in the macOS screen sharing feature, which enables remote access to the screen and control of the keyboard and mouse while the system is on.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.