Vulnerability Management

MacOS screen sharing vulnerability actively exploited for crypto mining

MacOS logo (Mac OS X), an operating system developed by Apple Inc., displayed on a MacBook Pro screen

Based on information from Ars Technica, Dutch officials have issued a warning regarding a high-severity vulnerability in macOS that is currently being actively exploited by attackers. The vulnerability allows for the execution of malicious code on affected systems.

The vulnerability, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and stems from a flaw in macOS' screen sharing capability. This flaw enables remote attackers to gain control of a Mac if port 5900 is accessible from the internet. The Netherlands National Cyber Security Centrum reported observing active abuse where attackers accessed root privileges and installed Monero crypto miners.

Apple released a patch for macOS Tahoe, Sequoia, and Sonoma last week. Security experts advise users to disable screen sharing when not in use, ensure port 5900 is not exposed to the internet, and connect via VPN or SSH tunneling as safer alternatives. While current exploits focus on crypto mining, there is a significant risk that attackers could leverage this vulnerability to deploy malware for credential theft or other malicious activities.

Source: Ars Technica

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds