The Dutch National Cyber Security Centre warns that the high‑severity macOS screen‑sharing vulnerability (CVE‑2026‑65400) is being actively exploited. Hackers can log in without a password, gain root access and install a Monero cryptominer.
Key Takeaways
- macOS screen‑sharing vulnerability (CVE‑2026‑65400) is under active exploitation
- Attackers gain root access and deploy Monero miners
- Apple released patches for macOS Tahoe, Sequoia, and Sonoma
Current Situation
The Netherlands National Cyber Security Centre (NCSC) reported that multiple internet‑exposed systems with port 5900 open have been compromised. In each case, the adversary obtained root privileges and installed a Monero cryptominer.
Technical Details
The flaw resides in the screen‑sharing component’s state‑management logic, allowing a remote party to view the screen and control keyboard‑mouse input. The vulnerability carries a CVSS score of 7.1 out of 10.
Apple’s Response
Apple issued a security update last week covering macOS versions Tahoe, Sequoia, and Sonoma. Users are urged to apply the patch immediately and disable public screen‑sharing where possible.
Why This Matters
BozokMedia analysis shows that compromised macOS machines can become part of large‑scale cryptomining botnets, draining electricity and exposing corporate networks to further infiltration.
"The exploitation of this screen‑sharing bug underscores the need for continuous patch management," says cybersecurity expert Dr. Emily Chen.
Frequently Asked Questions
Is my Mac at risk? If you have screen‑sharing enabled and haven’t installed the latest update, you are potentially exposed.
How can I protect myself? Apply the Apple patch immediately, block port 5900 with a firewall, and disable unnecessary screen‑sharing.