Discover your interests, together

Real deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Discover your interests, togetherReal deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Screen Sharing Exploit Under Attack: Patch Your Mac Now

Screen Sharing Exploit Under Attack: Patch Your Mac Now
Interest|Laptop Usage

A Critical macOS Screen Sharing Vulnerability You Cannot Ignore

The macOS Screen Sharing vulnerability is a critical authentication bug in Apple’s built-in remote desktop feature that lets attackers bypass login checks, gain root-level control, and install cryptomining malware on Macs with Screen Sharing exposed to the internet. If you enable Screen Sharing and leave it reachable on port 5900, you have effectively left your front door unlocked for anyone who knows this macOS exploit is active. This is not a theoretical issue to schedule for “someday.” Security agencies have already seen attackers break in and deploy Monero cryptominers, turning victim machines into silent, always-on money-makers for criminals while draining performance and power. Apple has issued an emergency Mac security patch, but tens of thousands of Macs remain unpatched and vulnerable, and attackers are scanning for them right now.

Screen Sharing Exploit Under Attack: Patch Your Mac Now

How the Screen Sharing Exploit Hands Over Your Mac

This macOS Screen Sharing vulnerability, tracked as CVE-2026-65400, stems from “insufficient state management during the authentication process” in Screen Sharing’s handling of connections over VNC on TCP port 5900. In plain language, the login logic is flawed: attackers can authenticate to macOS Screen Sharing without valid login credentials and end up with full interactive control. That means they can view your screen, control your keyboard and mouse, access files, run arbitrary code, and promote themselves to root. Security officials raised the severity score of this bug to 9.8 out of 10, calling it Critical, because the attack can be automated and leads to complete compromise. One researcher identified roughly 40,000 Macs with Screen Share enabled and reachable online, a massive attack surface that explains why this macOS exploit is active and attractive to criminals.

Screen Sharing Exploit Under Attack: Patch Your Mac Now

Cryptominer Attacks: What Happens After the Break-In

Once inside, attackers are not wasting time. Reports confirm that on systems where port 5900 was reachable, root access was obtained and a Monero crypto miner was installed in every observed case. That turns your Mac into a silent workhorse for someone else’s profit: CPU and GPU cycles get hijacked, fans spin harder, battery life drops, and the system slows as it strains under the cryptominer load. More worrying, a cryptominer attack on Mac is often the visible symptom of a deeper compromise. Anyone with root-level access can plant backdoors, steal data, or pivot into other devices on your network. Security authorities have already documented multiple systems compromised this way, confirming this is not a proof-of-concept lab trick but a live, ongoing campaign against unpatched Macs.

Patch Your Mac: Immediate Steps to Close the Exploit Window

The only responsible response is to apply the Mac security patch immediately. Apple released an emergency update on August 6 for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9, fixing the Screen Sharing authentication issue with improved state management. If you have not updated your MacBook or desktop Mac in the last few days, install the latest macOS update now; Apple itself has urged macOS users to upgrade. For those who cannot patch right away, disable Screen Sharing as a temporary shield: open System Settings, select General, then Sharing, and switch the Screen Sharing toggle off. That step closes port 5900 and blocks new remote connections via this flaw, but it is not a substitute for updating—leaving a known macOS screen sharing vulnerability unpatched is an open invitation to attackers.

Stay Ahead of Future macOS Exploits

The bigger lesson is that “set and forget” does not work for operating system security anymore. Apple does not release out-of-band updates unless something is critical, and this incident proves that point: a single authentication bug in Screen Sharing turned into a full remote-control pathway for attackers, who rapidly industrialized it into an automated cryptominer attack on Mac systems worldwide. Going forward, treat urgent macOS updates as non-negotiable maintenance, not optional extras. Turn on automatic updates, periodically check which services (like Screen Sharing) are exposed, and close anything you do not actively need. This time, the fix is available and well-documented; what matters now is whether users move fast enough to apply it. Update today, and this macOS exploit active in the wild becomes someone else’s problem instead of yours.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!