tech

Vulnerability giving attackers full control of Macs is under active exploitation

Screen-sharing bug lets remote hackers log in without a password.

Vulnerability giving attackers full control of Macs is under active exploitation

TL;DR

  • A high-severity macOS vulnerability (CVE-2026-65400) allowing attackers to execute malicious code is under active exploitation.
  • The vulnerability arises from a flaw in the macOS screen sharing feature, enabling remote control when port 5900 is exposed to the internet.
  • Attackers have been observed gaining root access and installing Monero crypto miners on affected systems.
  • Apple has released patches for macOS Tahoe, Sequoia, and Sonoma.
  • Security recommendations include blocking port 5900, using VPNs or SSH tunneling, and disabling screen sharing when not in use.