Apple and a Hacker's Future
My computer got compromised by a hacker who exploited a critical macOS vulnerability. Dutch officials have warned that this high-severity flaw, tracked as CVE-2026-65400, is actively being exploited on multiple machines with internet-accessible port 5900. Attackers can execute malicious code, access root, and install Monero crypto miners.
Apple patched the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma. The weakness stems from a bug in the macOS screen sharing feature, which allows remote parties to view the screen and control the keyboard and mouse while a system is on.
The vulnerability became public at Black Hat security conference. Apple said CVE-2026-65400 "may" enable an attacker without credentials to gain access to a Mac. Apple credited security firm Bynario for reporting the issue.
In my case, the always-on Mac Mini running only Claude and Codex saved me from potential disaster. I built an agent, Gecko, to track projects and gather information. It caught the malware by monitoring interactions and stopping commands when I invoked Claude. I used Claude to identify when the malware accessed the system for exactly four seconds, created a future detection tool, and wiped the Mac Mini.
Apple is wary of AI agents having full disk access on Macs, as the company released a developer note warning about the risks of granting such extensive permissions. I am concerned about the future implications of Apple's solution, but the Mac Mini's headless, always-on nature makes it an ideal host for my persistent agent, providing crucial protection against this vulnerability.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Apple and a Hacker’s Future stratechery.com