A vulnerability in the screen-sharing feature is being actively exploited on macOS
A vulnerability in macOS’s screen-sharing feature is being actively exploited by attackers, Ars Technica reports, citing the Netherlands National Cyber Security Center (NCSC). According to the agency, attacks were detected on several systems where port 5900 was accessible from the internet.
The issue is tracked under the identifier CVE-2026-65400. Apple released a patch for macOS Tahoe, Sequoia, and Sonoma a week earlier. The vulnerability received a severity rating of 7.1 out of 10. It is related to a bug in the state management mechanism of the Screen Sharing feature, which allows a remote user to view the computer’s screen and control the keyboard and mouse.
The NCSC stated that in all identified cases, attackers gained root access to the compromised devices and installed a Monero cryptocurrency miner. This program covertly uses the Mac’s computing resources to perform operations that generate cryptocurrency for the attackers.
For more breaking news, follow the UA.News Telegram channel.
Apple noted that CVE-2026-65400 could allow an unauthorized user without credentials to gain access to a Mac. Details of this vulnerability were made public during the Black Hat conference, which took place a week earlier.
Port 5900 is opened by the macOS firewall when screen sharing is enabled. Routers and some firewalls typically block this port unless it has been manually configured otherwise. Cybersecurity experts advise against leaving the port open to the internet and recommend using a VPN or SSH tunneling for remote access.
The article identifies the safest approach as disabling Screen Sharing when the feature is not needed. In macOS, this can be configured via System Settings → General → Sharing. Users are also advised to install the latest Apple security update.