Cybersecurity

Mac Users: Critical Screen Sharing Bug Is Being Actively Exploited Right Now — Here's What to Do

A critical macOS Screen Sharing flaw (CVE-2026-65400) is being actively exploited to give attackers full root access to Macs. Here's how to check your settings and protect your computer today.

Mac Users: Critical Screen Sharing Bug Is Being Actively Exploited Right Now — Here's What to Do

Do you have a Mac? There's one setting you need to check today — and depending on what you find, you may need to act immediately.

A critical security flaw in macOS is being actively exploited in the wild right now, giving attackers complete root access to affected computers. The Dutch National Cyber Security Centre (NCSC-NL) has confirmed it received reports of active abuse on multiple systems, and every single compromised machine shared one thing in common: a built-in macOS feature called Screen Sharing was reachable from the internet.

Here's what's happening, whether you're affected, and exactly what to do about it.


What Is Screen Sharing, and Why Does It Matter?

Screen Sharing is macOS's built-in remote desktop tool — it lets a remote party view your screen and control your keyboard and mouse while your Mac is turned on. It's the kind of feature that's genuinely useful when you need help from a friend or IT support remotely. When Screen Sharing is enabled, macOS opens TCP port 5900 on your network, which is the standard VNC port.

The problem is that Screen Sharing is disabled by default — but many users turn it on at some point and simply forget to turn it back off.


The Vulnerability: CVE-2026-65400

The flaw is tracked as CVE-2026-65400, and it's a nasty one. At its core, it's an authentication bypass — meaning attackers can connect to your Mac's Screen Sharing service without a valid username or password. Apple describes the bug as a failure in "state management" during authentication, essentially a logic error that lets a few correctly ordered network packets walk straight past the login process.

The NCSC-NL advisory puts it plainly: "Unauthorized individuals can perform authentication attempts that would normally not be accepted."

What's especially alarming is how quickly this went from "serious" to "critical." Tom's Hardware reports that CISA initially scored the vulnerability at 7.1 out of 10 on August 6, assuming an attacker needed some level of existing access. By August 14, CISA had revised that score all the way up to 9.8 out of 10 — the highest possible tier — after determining the attack requires no privileges whatsoever and can be fully automated.

Technical details of the bug were presented at last week's Black Hat security conference, and public proof-of-concept exploit code is now available.


What Attackers Are Doing With This Access

In every documented case so far, attackers obtained root access and installed a Monero cryptocurrency miner on the compromised machine. A Monero miner silently harnesses your Mac's CPU resources to perform mathematical operations that generate cryptocurrency for the attacker — you'd notice your Mac running hot, fans spinning constantly, and performance dragging, but you might not immediately know why.

Cryptomining is, relatively speaking, one of the less catastrophic things root access allows. Security Affairs notes this looks more like opportunistic, automated scanning than a targeted campaign — for now. Root access on a Mac could just as easily be used to steal passwords, install spyware, or deploy ransomware. The fact that attackers are currently content with coin mining doesn't mean that will stay true.

What makes this especially concerning is the speed at which working exploits are being built. Security Affairs reports that security firm Calif found no memory corruption or complex exploitation tricks in this flaw — just simple logic errors. Calif also said it built a working exploit for this vulnerability in approximately four hours using an AI coding agent. The gap between a patch release and a working exploit is shrinking fast.


Are You at Risk? Here's How to Check

The flaw only matters if Screen Sharing is enabled on your Mac and port 5900 is reachable from the internet. Most home routers will block that port by default, but if you've ever set up port forwarding, are on a business or university network, or aren't sure, you should check.

Step 1: Check if Screen Sharing is on

  1. Click the Apple menu () in the top-left corner
  2. Go to System Settings
  3. Click General
  4. Click Sharing
  5. Look for the Screen Sharing toggle

If it's switched off and you don't use it, you're in good shape. If it's on and you don't actively need it, turn it off right now.

Step 2: Install the macOS security update

Apple released a patch on August 6 — macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 all include the fix. To check for updates:

  1. Go to System Settings > General > Software Update
  2. Install any pending updates

This is not optional. Ars Technica is blunt about it: "Installing last week's security update is also a must."

Step 3: If you must keep Screen Sharing enabled

Security practitioners advise never exposing port 5900 directly to the internet. Instead, connect over a VPN or through SSH tunneling, and toggle Screen Sharing off when you're done with a session rather than leaving it running permanently.


A Note on the Patch Timeline

This is actually the second Screen Sharing patch Apple has released in about a month. Tom's Hardware notes that a related flaw, CVE-2026-43760, was fixed in late-July releases, though that earlier bug required valid credentials to exploit. CVE-2026-65400 requires nothing.

Security Affairs reports that researcher Alfredo Pesoli at Bynario Atlas was credited with discovering this latest vulnerability.


Not Sure What You're Looking At? We Can Help.

If you have a Mac and aren't confident about what these settings mean, or if your computer has been running unusually hot, slow, or sluggish lately, it may be worth having someone take a look. We work primarily with Windows PCs here at Computer Works in Yuba City, but we know plenty of local Mac users rely on us for guidance. If you suspect something is wrong with your machine, our virus removal service covers malicious software of all kinds — and we're happy to point you in the right direction.

The bottom line is simple: check that Screen Sharing toggle, install your macOS updates, and don't leave port 5900 exposed to the internet. It takes two minutes and could save you a serious headache.


Computer Works is located at 229 Clark Ave Suite E, Yuba City, CA. Mon–Fri, 9:30 AM – 5:00 PM. (530) 645-7007.

Related local service
Worried this could be malware?
If your computer has pop-ups, redirects, suspicious downloads, or ransomware warnings, start with our local virus removal page.
Tags
cybersecurity vulnerability patch-management apple web-security
Call Now