Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation
joshuark shares a report from Ars Technica: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet," the Netherlands National…
Dutch officials have warned that a critical vulnerability in macOS, tracked as CVE-2026-65400, is currently being exploited by attackers to gain full control of Mac computers. The National Cyber Security Centre (NCSC) in the Netherlands reported observations of the vulnerability being abused on multiple systems where port 5900 was accessible from the internet. Upon exploitation, the attackers gain root access and install a Monero crypto miner on the affected machine.
The vulnerability, rated 7.1 out of 10 in severity, stems from a flaw in macOS's screen sharing capability. Screen sharing allows a remote party to view the screen and control the keyboard and mouse of a machine while it's on. The root cause of the issue is a flaw in state management, which tracks system events, user interactions, variables, and other states.
The vulnerability was patched by Apple last week for macOS versions Tahoe, Sequoia, and Sonoma. However, CVE-2026-65400 was made public last week at the Black Hat security conference. Apple warned that the vulnerability may allow an attacker to gain access to a Mac without credentials. The discrepancy in language suggests caution on Apple's part when disclosing vulnerabilities.
Port 5900 is typically blocked by routers and dedicated firewalls, but if exposed to the Internet, it can be exploited. Screen sharing is enabled by macOS's firewall when port 5900 is open. Security experts advise Mac users to keep port 5900 closed unless screen sharing is required, and to connect via VPN or SSH tunneling instead. Screen sharing can be toggled on or off in System Settings > General > Sharing. Installing the patch from last week's security update is strongly recommended.
Written by urgent.news from Slashdot's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.