Tech

Dutch regulators warn of active exploitation of macOS screen-sharing flaw

Apple has patched the vulnerability in macOS Tahoe, Sequoia, and Sonoma, but the Netherlands National Cyber Security Centrum says attackers are already using the bug to install Monero miners.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Ars Technica · View original source
Vulnerability giving attackers full control of Macs is under active exploitation
CVE-2026-65400 allows unauthenticated root access when port 5900 is exposed

The Netherlands National Cyber Security Centrum (NCSC) has confirmed that a high-severity vulnerability in macOS is being actively exploited by remote attackers. The flaw, tracked as CVE-2026-65400, allows unauthenticated users to gain full root access to affected Macs when port 5900 is exposed to the internet.

According to the NCSC, the agency received notifications indicating that multiple systems with accessible port 5900 had been compromised. In all observed cases, attackers successfully obtained root access and deployed Monero crypto miners on the affected devices.

The vulnerability carries a severity rating of 7.1 out of 10 and stems from a bug in macOS screen-sharing state management. This component tracks preceding events, user interactions, and system states. A flaw in this logic allows a remote party to view the screen and control the keyboard and mouse without a password, provided the machine is turned on and the port is open.

Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week, following the public disclosure of the issue at the Black Hat security conference. In its disclosure, Apple stated that the vulnerability may allow an attacker without credentials to gain access to a Mac, a phrasing that security analysts note is common hedging language among technology developers.

Security practitioners advise that the risk is primarily triggered when screen sharing is enabled, as this causes the macOS firewall to open port 5900. While routers and dedicated firewalls typically block this port by default, users who override these settings are at risk. The NCSC recommends keeping the port closed, using VPNs or SSH tunneling for remote access, or disabling screen sharing entirely when not in use.

Although current exploitation is limited to Monero mining, there is a risk that attackers could use the vulnerability to install more severe malware, such as credential-stealing tools. Installing the latest security update remains the most effective defence against this specific threat.

Continue reading

More from Tech

Read next: Roborock’s Qrevo 2 Pro impresses WIRED as a budget robot vacuum
Read next: EuroBirdPortal maps bird movements across Europe
Read next: WIRED names Bose earbuds its top pick for noise cancellation in 2026 guide