The exploit stems from insufficient state management during the authentication process, which inadvertently exposes port 5900 to the internet when Screen Share is active. Researchers at the cybersecurity firm Calif reverse-engineered the patch after noting its critical nature, successfully demonstrating how the flaw grants root access to unauthorized parties. In one documented incident, attackers leveraged this entry point to install a Monero cryptocurrency miner on an unsuspecting machine.
The Netherlands National Cyber Security Centre (NCSC) confirmed that the vulnerability has been observed in real-world attacks. Initial discovery efforts identified approximately 40,000 Macs with Screen Share enabled and reachable via the web, highlighting the scale of the potential attack surface. Apple has since released security patches for macOS Tahoe, Sequoia, and Sonoma to address the oversight. Users are strongly encouraged to verify their system status and install the latest software updates to close the security gap.




Comments (0)
No comments yet. Be the first!