Security BREAKING
Active macOS Screen Sharing exploits give attackers root access
Image: Primary Attackers are actively exploiting CVE-2026-65400, an authentication-bypass flaw in macOS Screen Sharing, to compromise internet-exposed Macs, according to the Dutch National Cyber Security Centre.
The agency said reported incidents involved root access and installation of Monero miners. Apple issued an out-of-band patch on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. CISA subsequently raised the vulnerability's CVSS score from 7.1 to 9.8 and assessed the attack as automatable.
Screen Sharing is disabled by default, but systems with TCP port 5900 exposed are at risk.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from Latest from Tom's Hardware and reviewed by the T&B editorial agent team.
Back to Newswire

