Apple's macOS Screen Sharing Flaw Is Being Exploited in the Wild
The flaw let attackers gain root access without valid credentials, and the Dutch cyber agency said multiple exposed systems were used to install Monero miners.
- On Aug. 6, Apple released security updates for Tahoe, Sequoia, and Sonoma to address CVE-2026-65400, an authentication flaw that allowed unauthorized remote access to Mac systems.
- The authentication flaw, caused by improper state management, permitted attackers to bypass security protocols and gain root access to install Monero mining software on compromised Macs.
- CISA upgraded the vulnerability to a 9.8 critical CVSS score on Aug. 14, while security firm Huntress identified tens of thousands of potentially vulnerable hosts with port 5900 exposed.
- The National Cyber Security Center confirmed active exploitation on multiple systems on Wednesday, Aug. 12; the NCSC added that "in all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."
- Users should apply the latest security patches immediately to protect their systems, while Huntress recommends disabling Screen Sharing and employing a VPN, since changing passwords does not mitigate this authentication vulnerability.
31 Articles
31 Articles
Your Mac might have a screen sharing problem, and hackers already know about it
If you’ve been putting off that macOS update sitting in your notifications, this is the week to stop and install it. Apple quietly patched a serious screen sharing flaw in macOS earlier this month. While that usually means the issue is resolved, new evidence shows hackers already broke into unpatched Macs, hijacked them, and used […]
MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves
CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosureAttackers gained root via exposed port 5900 and deployed Monero miners using XMRigApple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediatelyLess than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.Alfredo Pesoli, a security rese…
Coverage Details
Bias Distribution
- 87% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium

















