Critical macOS Screen Share vulnerability requires immediate update

A severe authentication flaw in macOS Screen Share allows remote attackers to bypass credentials and seize control of a targeted computer. Tracked as CVE-2026-65400, the vulnerability exposes devices to unauthorized keyboard and mouse access, prompting urgent warnings from security agencies as evidence of active exploitation emerges in the wild.

Today, 12:16
1,662 0
Critical macOS Screen Share vulnerability requires immediate update

The exploit stems from insufficient state management during the authentication process, which inadvertently exposes port 5900 to the internet when Screen Share is active. Researchers at the cybersecurity firm Calif reverse-engineered the patch after noting its critical nature, successfully demonstrating how the flaw grants root access to unauthorized parties. In one documented incident, attackers leveraged this entry point to install a Monero cryptocurrency miner on an unsuspecting machine.

The Netherlands National Cyber Security Centre (NCSC) confirmed that the vulnerability has been observed in real-world attacks. Initial discovery efforts identified approximately 40,000 Macs with Screen Share enabled and reachable via the web, highlighting the scale of the potential attack surface. Apple has since released security patches for macOS Tahoe, Sequoia, and Sonoma to address the oversight. Users are strongly encouraged to verify their system status and install the latest software updates to close the security gap.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!