Digital Event Horizon
A critical vulnerability in macOS has been identified as a major security threat, allowing attackers to gain full control of Macs under active exploitation. Learn more about the vulnerability and how to protect yourself from this potential attack.
CVE-2026-65400 vulnerability in macOS allows attackers to gain full control of Macs under active exploitation. The vulnerability is linked to a bug in the screen sharing capability, which enables remote control of a Mac. Attackers can exploit the vulnerability to install malware that can steal credentials or perform other nefarious activities. Dutch officials have warned that the vulnerability is being actively exploited, allowing attackers to gain access to Macs without credentials. Mitigation recommendations include keeping the port closed, using a VPN or SSH tunneling, and blocking screen sharing unless necessary.
A high-severity vulnerability in macOS, tracked as CVE-2026-65400, has been identified as a major security threat, allowing attackers to gain full control of Macs under active exploitation. The vulnerability is linked to a bug in the macOS screen sharing capability, which enables a remote party to view the screen and control the keyboard and mouse while a machine is turned on. The flaw in the "state management" system, which keeps track of preceding events, user interactions, variables, and other system states, creates an opening for attackers to exploit.
Dan Goodin, Senior Security Editor at Ars Technica, notes that the vulnerability has been observed on multiple systems where port 5900 was accessible from the internet, and in all cases, root access had been gained on the affected system, with a Monero crypto miner being installed. This suggests that the vulnerability is being exploited by attackers to install malware that can steal credentials or perform other nefarious activities.
The vulnerability is being actively exploited, with Dutch officials warning that it has been observed in cases where port 5900 was accessible from the internet. The Netherlands National Cyber Security Centrum (NCSC) has warned that the vulnerability allows an attacker without credentials to gain access to a Mac, and it is unclear why Apple hedged when disclosing the vulnerability.
To mitigate the risk, security practitioners recommend that Mac users keep the port closed, even when using screen sharing, and instead connect over a VPN or through SSH tunneling. The safest practice is to block screen sharing, enable it only when screen sharing is needed, and turn the feature off once a session has ended. Users can also install last week's security update to patch the vulnerability.
It is worth noting that the current exploits are limited to installing Monero miners, which surreptitiously harness a Mac's resources to perform mathematical operations that generate the cryptocurrency for the attacker. However, a bigger risk is that attackers might exploit the vulnerability to install malware that steals credentials or performs other more nefarious activities.
In conclusion, the CVE-2026-65400 vulnerability highlights the importance of keeping software up to date and being cautious when using screen sharing features. Users should take immediate action to patch the vulnerability and follow best practices to minimize the risk of exploitation.
Related Information:
https://www.digitaleventhorizon.com/articles/Vulnerability-Giving-Attackers-Full-Control-of-Macs-Under-Active-Exploitation-deh.shtml
https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/
https://jmacweb.com/ai-news/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-20260815
Published: Sat Aug 15 23:45:11 2026 by llama3.2 3B Q4_K_M