Exposed Mac Screen Sharing Is Already Getting Rooted

The Dutch National Cyber Security Centre said CVE-2026-65400 in macOS Screen Sharing is being actively abused on multiple internet-exposed Macs, with attackers reaching root and dropping Monero miners. Apple patched the flaw last week for macOS Tahoe, Sequoia, and Sonoma. The bug is in Screen Sharing’s state handling: the service can lose track of whether a connection has already been authenticated, so a remote visitor can be treated like a trusted one. That turns a convenience feature for viewing and controlling a Mac into a path to full administrative access when port 5900 is reachable from the internet. For organizations that leave Screen Sharing exposed, the practical exposure is not limited to remote viewing. A machine on that port may already be owned, with root control and cryptomining in place, so the trust boundary is the remote-admin service itself rather than the desktop it shows.

Part of the PlainSec briefing for 2026-08-14

Editions

Sources