Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors are exploiting a recently patched macOS vulnerability to gain root access and deploy cryptominers.
The exploited bug, tracked as CVE-2026-65400, is a high-severity authentication issue in Screen Sharing that allows remote attackers to log in without valid credentials.
Apple disclosed the flaw on August 6, when it rolled out fixes in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.
Roughly a week later, the Dutch National Cyber Security Centrum (NCSC) warned that in-the-wild exploitation has started, fueled by the existence of a public proof-of-concept (PoC) exploit.
“The NCSC has received a notification showing that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the internet,” NCSC says.
Threat actors have been exploiting the security defect to gain root access to the vulnerable systems and install a Monero miner, it says.
Advertisement. Scroll to continue reading.
“Apple has...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE