Apple Screen Sharing flaw is now being exploited, making macOS updates essential
Apple’s macOS Screen Sharing flaw is being actively exploited, with attackers gaining root access and installing crypto-mining software.
Apple has issued an urgent warning to Mac users after confirming that a serious vulnerability in its built-in Screen Sharing service is being actively exploited. The flaw, tracked as CVE-2026-65400, can allow attackers to bypass authentication and gain extensive control over an affected Mac. The vulnerability was initially treated as a serious security concern when Apple released an emergency fix. Still, evidence from the Netherlands now shows that attackers are using it against real systems.
Table Of Content
The Netherlands National Cyber Security Centre (NCSC-NL) reported that it had received notifications involving the vulnerability on “multiple systems”. In every case reported to the agency, attackers were able to obtain root access and install cryptocurrency-mining software. The development makes Apple’s security update more urgent for anyone with Screen Sharing enabled, particularly when the service is accessible beyond a trusted local network.
Attackers can gain powerful access to affected Macs
The vulnerability affects the Screen Sharing Server component of macOS. Screen Sharing is Apple’s built-in remote desktop feature, allowing users to view and control a Mac from another computer. Apple describes the feature as allowing remote users to see the Mac’s desktop and interact with files, windows and applications. The newly exploited flaw allows an attacker to bypass the normal authentication process, turning the feature into a potential entry point for unauthorised access.
The danger is particularly significant because successful exploitation can provide root-level access. That gives an attacker extensive control over the operating system, including the ability to access or modify files and install additional software. According to the Dutch authorities, the attackers observed in the wild used that access to deploy cryptocurrency-mining software, effectively turning compromised Macs into resources for generating cryptocurrency.
The vulnerability was initially given a CVSS score of 7.1, placing it in the high-severity category. That assessment has since changed. CISA raised the score to 9.8 on 14 August after determining that the vulnerability could be exploited without credentials and could result in a complete compromise of confidentiality, integrity and availability. The agency also subsequently assessed the vulnerability as automatable, increasing concerns about attacks being carried out at scale.
Apple has already released emergency updates
Apple released out-of-band security updates on 6 August specifically to address CVE-2026-65400. The fixes are included in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. The company had already released broader security updates on 27 July, but the additional August release shows the Screen Sharing problem required a separate, more immediate response.
Apple’s security documentation describes the underlying problem as an authentication issue that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. The company addressed the problem through improved state management during authentication. Users running affected versions should therefore install the relevant update rather than relying on the earlier July security releases.
The risk is greatest when Screen Sharing is enabled, and an attacker can reach the service. TCP port 5900 is associated with macOS Screen Sharing, and systems with that port exposed directly to the internet face a substantially greater risk. Screen Sharing is disabled by default, meaning Macs that have never had the feature enabled are not exposed to this particular attack path.
For users who do not need remote access, disabling Screen Sharing provides another layer of protection. Apple places the setting under System Settings, General and Sharing. Users who require remote access should also avoid exposing port 5900 directly to the public internet and should instead use appropriate network protections.
The warning comes amid more screen-sharing security problems
The macOS incident is part of a wider series of security problems involving remote access and screen-sharing technology. Screen-sharing features are attractive targets because they are designed to provide powerful remote control, meaning a successful attack can potentially give criminals access to sensitive information and system functions without needing physical access to a computer. The recent exploitation of Apple’s vulnerability demonstrates how quickly a theoretical security problem can become an operational threat.
The situation also follows the disclosure of a separate serious vulnerability in Zoom. Researchers recently reported a flaw in Zoom’s annotation system that could allow an attacker to take control of another participant’s device during a meeting. Zoom subsequently issued patches, with the incident highlighting similar concerns around software that enables remote interaction between computers.
For Mac users, the immediate priority is straightforward: install the latest available security update if Screen Sharing is enabled or if the Mac could otherwise be exposed to the vulnerable service. Apple currently lists macOS Tahoe 26.6, Sequoia 15.7.8, and Sonoma 14.8.8 as its 27 July releases, but the later emergency versions addressing CVE-2026-65400 are 26.6.1, 15.7.9, and 14.8.9, respectively. Users should check Software Update and confirm that their systems have received the newer security fixes.
With attackers already using the vulnerability in the wild and cryptocurrency miners being installed on compromised machines, leaving an affected Mac unpatched carries a real security risk. The flaw may have initially seemed like a problem users could address at their convenience, but reports from the Netherlands have changed that calculation. Updating macOS, disabling Screen Sharing when it is not required and keeping port 5900 away from the public internet are sensible steps to reduce the risk of compromise.







