Critical MacOS Vulnerability Exploited via Screen Sharing Exploit

A critical macOS vulnerability allowing unauthorized system control via screen-sharing is currently being exploited, according to Ars Technica. This security flaw, identified as CVE-2026-65400, is under active exploitation and presents significant risks for Mac users.
The vulnerability, which received a severity rating of 7.1 out of 10, exploits a bug in macOS's ability to manage screens shared remotely. Hackers can view screens and control devices remotely if they gain access through port 5900 without needing credentials. Details about this flaw emerged during last week's Black Hat security conference.
Apple released a patch for the issue last week for macOS versions Tahoe, Sequoia, and Sonoma. However, the precise impact and scale of exploitation remain somewhat ambiguous, as Apple has used cautious language, saying the vulnerability 'may' allow access, which is typical in tech disclosures, TechCrunch reports.
The Netherlands National Cyber Security Centrum (NCSC) has noted that several systems with open port 5900 have been compromised. Affected systems have been used to deploy Monero cryptocurrency miners, exploiting system resources for unauthorized cryptomining.
Security experts advise users to disable screen sharing unless absolutely necessary and to use VPNs or SSH tunneling if remote access is needed. This ensures that port 5900 remains closed, minimizing the chances of unauthorized access.
Currently, the primary observed malicious activity involves cryptomining, but the potential for more damaging exploits exists, including malware that could steal sensitive data or deeper system infiltration.
Mac users are strongly urged to install the recent security updates and remain vigilant about their system settings. Keeping ports closed and enabling screen sharing only as needed are critical steps for maintaining security.
This situation underlines the importance of rapid response and patch management to mitigate such vulnerabilities. Ongoing vigilance and timely updates are essential in protecting systems from emerging threats.