← Back to feed
Vulnerabilities & PatchesEmerging2 sourcesAug 17, 2026 · 10:56via Malwarebytes Labs

Update your Mac: Screen Sharing vulnerability exploited in the wild

Brief

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers.

The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials. macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900.

Successful exploitation can allow a remote attacker on a reachable network to authenticate to the service without legitimate credentials. Apple said the bug was fixed through “improved state management,” which suggests an authentication-flow or session-state validation failure rather than a cryptographic break. The patch was issued for macOS Tahoe 26. 6.

Read more on Malwarebytes Labs

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Malwarebytes LabsPrimary··trust 1.28

Update your Mac: Screen Sharing vulnerability exploited in the wild

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers .

The vulnerability, tracked as CVE-2026-65400 , was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials.

macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900. Successful exploitation can allow a remote attacker on a reachable network to authenticate to the service without legitimate credentials.

Apple said the bug was fixed through “improved state management,” which suggests an authentication-flow or session-state validation failure rather than a cryptographic break.

The patch was issued for macOS Tahoe 26. 6. 1, Sequoia 15. 7. 9, and Sonoma 14. 8. 9. Practical exposure requires Screen Sharing to be enabled, so the highest-risk systems are those where port 5900 is internet-accessible, typically through a router port-forward, public IP assignment, or hosting-provider setup.

Hosts reachable only from an internal network are still potentially exposed, but attackers would have to gain a position on that network.

An attacker could view and control the Mac remotely because that is the function Screen Sharing provides. NCSC says active cases involved attackers gaining root access and installing cryptomining software, specifically for Monero mining.

The criminals likely chose Monero mining because it does not depend on heavily specialized, application-specific integrated circuits (ASICs), but can be done with any CPU or GPU.

Cryptomining isn’t necessarily the worst an attacker could do. With a root-level compromise an attacker could enable persistence, data theft, credential and key harvesting, deployment of additional malware, and lateral movement.

Read more →
Malware.news··trust 0.88

Update your Mac: Screen Sharing vulnerability exploited in the wild

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers.

The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials. macOS’s built-in Screen Sharing service is a remote-control feature commonly associated with port 5900.

Successful exploitation can allow a remote attacker on a reachable network to authenticate to the service without legitimate credentials. Apple said the bug was fixed through “improved state management,” which suggests an authentication-flow or session-state validation failure rather than a cryptographic break. The patch was issued for macOS Tahoe 26. 6. 1, Sequoia 15. 7. 9, and Sonoma 14. 8. 9.

Practical exposure requires Screen Sharing to be enabled, so the highest-risk systems are those where port 5900 is internet-accessible, typically through a router port-forward, public IP assignment, or hosting-provider setup. Hosts reachable only from an internal network are still potentially exposed, but attackers would have to gain a position on that network.

An attacker could view and control the Mac remotely because that is the function Screen Sharing provides. NCSC says active cases involved attackers gaining root access and installing cryptomining software, specifically for Monero mining. The criminals likely chose Monero mining because it does not depend on heavily specialized, application-specific integrated circuits (ASICs), but can be done with any CPU or GPU.

Read more →