Dutch agency warns active exploitation of critical macOS screen-sharing flaw
The Netherlands National Cyber Security Centre says a high-severity macOS vulnerability is being actively abused, with attackers gaining root access and installing a Monero miner.
The Netherlands National Cyber Security Centre has issued an alert that the CVE-2026-65400 vulnerability in macOS screen sharing is under active exploitation. The agency observed multiple Internet-exposed machines with port 5900 open, where attackers achieved root access and installed a Monero mining payload. Apple responded by releasing a security update for macOS Tahoe, Sequoia, and Sonoma, addressing the flaw that allows unauthenticated remote control of the keyboard and mouse.
The bug, assigned a severity score of 7.1 out of 10, originates from a defect in the screen-sharing state-management logic. Details of the vulnerability were disclosed at last week’s Black Hat security conference, and a video demonstrating the exploit was made public. Apple’s statement noted that the issue “may” permit credential-less access, reflecting typical cautious language in vulnerability disclosures.
Why it matters
Unpatched Macs can be hijacked to run illicit crypto miners, exposing users to data loss and financial harm.
In this story
