macOS Screen Sharing Flaw Actively Exploited; Apple Ships Patches

macOS Screen Sharing Flaw Actively Exploited; Apple Ships Patches

Attackers are exploiting CVE-2026-65400, a macOS Screen Sharing authentication bypass, to gain root access and deploy Monero cryptocurrency miners, per the Dutch NCSC. Exploitation requires port 5900 exposed to the network. Apple patched Tahoe, Sequoia, and Sonoma on August 6 (macOS 26.6.1, 15.7.9, 14.8.9). Administrators should update and close that port.

Published

Read at another depth