{
  "id": 1065096,
  "title": "Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation",
  "url": "https://urgent.news/2026/08/15/vulnerability-giving-attackers-full-control-of-macs-is-under-active",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-15T15:00:00.000Z",
  "source": {
    "name": "Slashdot",
    "slug": "slashdot",
    "url": "https://apple.slashdot.org/story/26/08/14/2213230/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation"
  },
  "original_language": "en",
  "account": "Dutch officials have warned that a critical vulnerability in macOS, tracked as CVE-2026-65400, is currently being exploited by attackers to gain full control of Mac computers. The National Cyber Security Centre (NCSC) in the Netherlands reported observations of the vulnerability being abused on multiple systems where port 5900 was accessible from the internet. Upon exploitation, the attackers gain root access and install a Monero crypto miner on the affected machine.\n\nThe vulnerability, rated 7.1 out of 10 in severity, stems from a flaw in macOS's screen sharing capability. Screen sharing allows a remote party to view the screen and control the keyboard and mouse of a machine while it's on. The root cause of the issue is a flaw in state management, which tracks system events, user interactions, variables, and other states.\n\nThe vulnerability was patched by Apple last week for macOS versions Tahoe, Sequoia, and Sonoma. However, CVE-2026-65400 was made public last week at the Black Hat security conference. Apple warned that the vulnerability may allow an attacker to gain access to a Mac without credentials. The discrepancy in language suggests caution on Apple's part when disclosing vulnerabilities.\n\nPort 5900 is typically blocked by routers and dedicated firewalls, but if exposed to the Internet, it can be exploited. Screen sharing is enabled by macOS's firewall when port 5900 is open. Security experts advise Mac users to keep port 5900 closed unless screen sharing is required, and to connect via VPN or SSH tunneling instead. Screen sharing can be toggled on or off in System Settings > General > Sharing. Installing the patch from last week's security update is strongly recommended.",
  "summary": "joshuark shares a report from Ars Technica: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. \"The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,\" the Netherlands National…",
  "key_points": [
    "Dutch officials warn CVE-2026-65400 vulnerability exploited on Macs",
    "Attackers gain root access, install Monero crypto miner",
    "Apple patched vulnerability for Tahoe, Sequoia, Sonoma versions"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}