Apple has released a patch for a high-severity macOS vulnerability that allows unauthorized remote access via the screen sharing feature. Dutch security officials report the flaw is currently being exploited to gain root access and install Monero cryptocurrency miners on systems with exposed ports.
Discovery of Active Exploitation
The Netherlands National Cyber Security Centrum (NCSC) issued a stern warning following the discovery of active attacks leveraging a critical vulnerability in macOS. Security researchers identified that attackers are specifically targeting systems where port 5900 is accessible from the open internet. By exploiting this network exposure, malicious actors are gaining root-level control over compromised devices. Once they achieve this level of administrative access, the attackers are deploying Monero cryptocurrency mining software, which leverages the hijacked computer's processing power to generate digital currency for the perpetrators. This form of 'cryptojacking' essentially turns unsuspecting user hardware into tools for the attacker’s financial gain, often leading to performance degradation and increased power consumption on the affected Mac machines.
Technical Root Cause Analysis
Tracked as CVE-2026-65400, the flaw resides within the macOS screen sharing component, a feature that typically allows users to view and control their desktop remotely. The vulnerability is fundamentally rooted in a failure of 'state management'—the logic the system uses to track user interactions, system variables, and previous events during a remote session. Because this management logic is flawed, an attacker can bypass traditional authentication methods to gain unauthorized control of the machine’s keyboard and mouse. The security researchers who discovered the issue noted that the bug allows a remote party to interface with the operating system as if they were a legitimate, authenticated user. Apple officially acknowledged this risk, confirming that the flaw permits unauthorized individuals to gain access to a computer without needing valid credentials, despite using cautious language during their initial disclosure.
Industry Disclosure and Response
The details surrounding CVE-2026-65400 reached a wider audience during the recent Black Hat security conference, where the mechanism of the exploit was shared with the professional cybersecurity community. This public disclosure highlighted the urgency of the situation, as the vulnerability had already been under active abuse in the wild. Apple took action by issuing a patch for the affected operating systems—Tahoe, Sequoia, and Sonoma—last week. While the company's official security advisory suggested that the vulnerability 'may' allow unauthorized access, the NCSC's report indicates that the threat is concrete and already resulting in system compromises. The discrepancy in language between developers and security agencies is not unusual, but it highlights the necessity for users to apply security updates as soon as they are made available by the manufacturer to mitigate risks.
⚖ The Balanced View
Supporting view
The NCSC maintains that the vulnerability represents a significant risk to systems with exposed port 5900, as active cryptojacking has been observed on multiple real-world systems.
Concerns & criticism
Apple opted for cautious, non-committal language in its security documentation regarding the potential for unauthorized access, choosing to state that the flaw 'may' allow such entry rather than definitively confirming it for every scenario.
→What's next
Users of macOS Tahoe, Sequoia, and Sonoma are strongly encouraged to verify that their systems are fully updated to the latest version. Additionally, users should confirm that port 5900 is not exposed to the public internet to prevent further unauthorized access attempts.










































































































































































































