Critical Apple macOS Screen Sharing Flaw Is Being Actively Exploited

Critical Apple macOS Screen Sharing Flaw Is Being Actively Exploited

A serious security flaw in Appleโ€™s macOS Screen Sharing feature is now being actively exploited, putting Macs that have remote screen access exposed to the internet at increased risk.

The vulnerability is tracked as CVE-2026-65400. It affects the authentication process used by macOS Screen Sharing and could allow an attacker who can reach the service over a network to get past normal login checks without valid credentials. Apple fixed the issue by improving how macOS manages the authentication state during Screen Sharing connections.

The problem is especially concerning because Screen Sharing can provide remote access to a Mac. Once unauthorized access is gained, an attacker may be able to interact with the affected computer and potentially use that access for additional malicious activity.

Recent attacks show that the threat is no longer only theoretical. Active exploitation has been observed against Macs where port 5900, commonly used for Screen Sharing and VNC connections, was directly accessible from the internet. In reported cases, attackers were able to obtain root-level access and install software designed to mine the Monero cryptocurrency.

Cryptocurrency mining malware uses a victimโ€™s computer resources to generate digital currency for an attacker. This can cause unusually high processor usage, slower system performance, increased power consumption and other problems. However, root access can potentially be used for much more serious attacks than cryptocurrency mining, making the vulnerability particularly important for businesses and organizations using Macs for development, servers or remote administration.

Apple has already released security updates that fix CVE-2026-65400. The vulnerability was patched in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9, which were released on August 6, 2026.

Mac users should install the latest available macOS security update as soon as possible. Organizations managing multiple Macs may also want to check whether Screen Sharing is enabled on systems that do not require it and make sure the Screen Sharing service is not unnecessarily exposed directly to the public internet.

Simply changing passwords may not be enough to solve the underlying problem because the flaw affects the authentication process itself. Installing Appleโ€™s security update is therefore the most important step for permanently closing the vulnerability on affected Macs.

The incident also highlights the risks of exposing remote-management services directly to the internet. Features such as Screen Sharing can be useful for technical support and remote administration, but vulnerabilities in these services can give attackers a valuable entry point when systems are not quickly updated.

With real-world attacks now being reported, users and IT teams running older macOS versions should check their systems immediately and apply the patched releases rather than waiting for a normal update cycle.

Previous Article

Anthropicโ€™s Quarterly Revenue Reportedly Jumps Above $11.5 Billion