Exposed Mac Screen Sharing Is Already Getting Rooted
The Dutch National Cyber Security Centre said CVE-2026-65400 in macOS Screen Sharing is being actively abused on multiple internet-exposed Macs, with attackers reaching root and dropping Monero miners. Apple patched the flaw last week for macOS Tahoe, Sequoia, and Sonoma.
The bug is in Screen Sharing’s state handling: the service can lose track of whether a connection has already been authenticated, so a remote visitor can be treated like a trusted one. That turns a convenience feature for viewing and controlling a Mac into a path to full administrative access when port 5900 is reachable from the internet.
For organizations that leave Screen Sharing exposed, the practical exposure is not limited to remote viewing. A machine on that port may already be owned, with root control and cryptomining in place, so the trust boundary is the remote-admin service itself rather than the desktop it shows.