Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.
Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.
βThe NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,β the Netherlands National Cyber Security Centrum warned earlier this week. βIn all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.β
Do you know if your screen sharing is on?
The vulnerability
The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. With a severity rating of 7.1 out of 10, it stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on.
A flaw in the βstate management,β which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last weekβs Black Hat security conference.
Appleβs disclosure
Apple said last week that CVE-2026-65400 βmayβ allow an attacker without credentials to gain access to a Mac. Itβs unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.
Comments
No comments yet. Start the discussion.