August 31, 2026ADMIN

Actively Exploited macOS Screen Sharing Flaw Gives Attackers Root Access

Dutch cybersecurity officials say attackers are exploiting a macOS screen sharing flaw to gain root access and install Monero miners.

Actively Exploited macOS Screen Sharing Flaw Gives Attackers Root Access

A high-severity vulnerability in macOS screen sharing is being actively exploited, according to a warning from the Netherlands National Cyber Security Centrum (NCSC). The security flaw can allow attackers to execute malicious code on affected Macs, and officials say compromised systems were accessed with root privileges.

Apple has released patches for macOS Tahoe, Sequoia, and Sonoma. Mac users and administrators should update supported systems and determine whether screen sharing is unnecessarily exposed to the Internet.

What is known about the attacks

The vulnerability is tracked as CVE-2026-65400 and has a severity score of 7.1 out of 10. The NCSC said it received a notification showing that attackers had actively abused the flaw on multiple systems.

The affected systems shared a notable configuration: port 5900 was accessible from the Internet. According to the agency, attackers obtained root access in each of the observed cases and installed a Monero cryptocurrency miner.

Root access provides extensive control over a system. In the incidents described by the NCSC, that level of access allowed the attackers to place unauthorized cryptocurrency-mining software on the compromised Macs.

The warning establishes that exploitation has occurred on multiple Internet-accessible systems. It does not indicate how many Macs may remain vulnerable or suggest that every Mac with screen sharing enabled has been compromised.

How the macOS vulnerability works

CVE-2026-65400 stems from a bug in the state management of macOS screen sharing. State management is the mechanism software uses to keep track of information such as:

  • Previous events
  • User interactions
  • Variables
  • Other relevant system states

The flaw affects the built-in screen sharing capability, which can let a remote party view a Mac’s screen and control its keyboard and mouse while the computer is turned on. Because this feature provides direct interaction with the machine, a security failure in how it manages its state can have serious consequences.

In the attacks reported by Dutch officials, exploitation went beyond remote viewing or ordinary screen control. Attackers reached root access and installed a Monero miner, demonstrating the potential impact of leaving a vulnerable service exposed.

Which macOS versions received patches

Apple released fixes for three current macOS product lines:

  • macOS Tahoe
  • macOS Sequoia
  • macOS Sonoma

Users running one of these versions should install the available update. Applying the patch addresses the underlying vulnerability and is especially important for Macs that use screen sharing or have port 5900 reachable from the public Internet.

The available information identifies these three macOS lines as having received fixes. It does not provide details about other releases, so users should rely on the update options and security information available for their own Macs rather than assuming an unlisted version is affected or unaffected.

Why Internet exposure matters

The NCSC’s report specifically connects the observed compromises with systems on which port 5900 was accessible from the Internet. That detail gives Mac owners and IT teams a clear configuration to review alongside installing Apple’s patch.

A practical response includes checking whether screen sharing is enabled, whether it is required, and whether its associated port can be reached directly from outside the local network. If remote access is not needed, removing that exposure reduces the opportunity for Internet-based attackers to interact with the service.

Organizations should also review systems that previously exposed port 5900. Installing the update prevents continued exposure to the patched flaw, but the NCSC warning shows that exploitation was already taking place. A system that was vulnerable and publicly reachable may therefore warrant examination for signs of unauthorized root access or an installed Monero miner.

The reported mining activity is the observed payload in these incidents. The available warning does not describe other payloads, identify the attackers, or explain how broadly they are scanning for vulnerable Macs.

What Mac users should do now

The most direct protective steps follow from the information disclosed by Apple and the NCSC:

  1. Identify whether the Mac runs Tahoe, Sequoia, or Sonoma.
  2. Install the security update Apple released for the relevant version.
  3. Check whether macOS screen sharing is enabled and still needed.
  4. Determine whether port 5900 is accessible from the Internet.
  5. Review previously exposed systems for unauthorized root access or cryptocurrency-mining software.

Individual users may not intentionally expose screen sharing, so it is worth checking rather than assuming the feature is off. Administrators responsible for multiple Macs should prioritize systems with public Internet exposure because that configuration was present in every case cited by the Dutch agency.

Conclusion

CVE-2026-65400 is not only a theoretical macOS risk: Dutch cybersecurity officials say it has been exploited on multiple systems with Internet-accessible port 5900. The observed attackers gained root access and installed Monero miners. Apple’s patches for Tahoe, Sequoia, and Sonoma should be applied promptly, while screen sharing and public port exposure should be reviewed at the same time.

Original reporting: Ars


Originally reported by Ars.