Discover your interests, together

Real deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Discover your interests, togetherReal deals, honest reviews and shopping stories from people who share your interests — every day on Milik.

Critical macOS Screen Sharing Flaw Under Active Exploit

Critical macOS Screen Sharing Flaw Under Active Exploit
Interest|Laptop Usage

This macOS Screen Sharing exploit demands your attention now

The macOS Screen Sharing vulnerability tracked as CVE-2026-65400 is a critical macOS security vulnerability that lets attackers bypass Screen Sharing authentication, seize keyboard and mouse control, gain root access, and install Monero cryptominers on exposed Macs when Screen Sharing is enabled and reachable over the internet. If you are treating this as a routine bug, you are underestimating it. This is remote, credential‑less compromise of your Mac’s core controls—exactly the scenario Screen Sharing was never supposed to allow. Attackers do not need your password; they need an open port and an unpatched system. When security researchers say Apple “does not ship an update out of band unless something is critical,” they are spelling out that this is not optional maintenance—it is an emergency fix you ignore at your own risk.

Critical macOS Screen Sharing Flaw Under Active Exploit

How the Screen Sharing exploit works—and why cryptominers love it

This Screen Sharing exploit is powered by an authentication bug in macOS’s built‑in remote desktop tool. When Screen Sharing is activated, macOS opens port 5900 through its firewall to the outside world. Because of “insufficient state management during the authentication process,” attackers can trick the service into accepting authentication attempts that should be rejected, letting them log in without valid credentials and control your keyboard and mouse. Once inside, they escalate to root, the highest level of system privilege, and from there it is trivial to drop malware. In multiple observed cases, that malware has been a Monero cryptominer running under root, quietly hijacking your CPU cycles for someone else’s profit. A cryptominer attack at root is not harmless background noise; it can degrade performance, shorten hardware lifespan, and mask further compromise behind constant activity.

Critical macOS Screen Sharing Flaw Under Active Exploit

Who is at risk: more Macs than you think

If you use a MacBook or desktop Mac and have not installed the latest system update in the past week, you should assume you are at risk. The Screen Sharing exploit matters most when port 5900 is reachable from the internet, which is exactly how many remote‑access setups operate. The first researcher to uncover the issue found about 40,000 Macs with Screen Sharing enabled and exposed online, a stark indicator of the potential target pool. Any macOS Tahoe, Sequoia, or Sonoma machine running a version prior to the recent Mac security patch is vulnerable, and attackers are already hitting systems where that port is open. One advisory notes that on multiple compromised machines, attackers gained root access and deployed a Monero cryptominer. The takeaway: this is not a theoretical flaw sitting in a database—it is a live Screen Sharing exploit against real Macs, right now.

Apple’s emergency fix: update or disable Screen Sharing immediately

There is no excuse to stay exposed, because Apple has already shipped the Mac security patch. The company fixed the Screen Sharing exploit with updates to macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1), explicitly addressing the authentication issue with improved state management. Mac users are urged to install the latest security update without delay. If your MacBook or desktop Mac has not been updated in the last week, treat “install that latest update now” as a direct instruction. For users who cannot patch immediately—for example, in tightly controlled enterprise environments—the only responsible workaround is to disable Screen Sharing manually by opening System Settings, selecting General, then Sharing, and turning the Screen Sharing toggle off. Leaving Screen Sharing active on an unpatched macOS release is equivalent to leaving a remote‑control backdoor open to anyone who finds your exposed port.

Conclusion: take this Screen Sharing exploit seriously

This Screen Sharing exploit is the kind of macOS security vulnerability that separates careful system owners from victims: it is remote, actively abused, and already dropping Monero cryptominers on unpatched Macs. Minimizing it because “it’s only Screen Sharing” is a mistake; Screen Sharing is a direct line into your system, and CVE-2026-65400 turned that line into an attacker’s shortcut to root. Apple’s out‑of‑band fix and repeated calls to update underline that this is a critical threat, not a routine bugfix. If you care about the integrity, performance, and lifespan of your Mac, the path is clear: update Tahoe, Sequoia, or Sonoma to the latest release, or disable Screen Sharing until you can. Ignoring a known Screen Sharing exploit while cryptominer attacks are actively ongoing is not caution—it is negligence.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!