As cited
Citation snapshot as of .
vulnerabilities
Vulnerability giving attackers full control of Macs is under active exploitation
A high-severity macOS vulnerability (CVE-2026-65400) in the screen sharing feature allows remote code execution with root privileges and is currently being exploited in the wild. The Netherlands National Cyber Security Centrum reported active abuse on systems with port 5900 exposed to the internet, where attackers installed Monero crypto miners after gaining access. Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week.
Why it matters: Mac users with screen sharing enabled and port 5900 exposed need to patch immediately; attackers are actively deploying crypto miners and establishing root access on vulnerable systems.
- Source published
- First seen by Cybersecurity Tracker