A recent macOS vulnerability is being exploited in real-world attacks, allowing hackers to gain root access and deploy cryptominers on vulnerable systems. The flaw, tracked as CVE-2026-65400, affects Screen Sharing, a built-in feature that allows users to remotely control another Mac’s screen.
The bug was patched by Apple just over a week ago, but threat actors have already begun exploiting it in the wild. The Dutch National Cyber Security Centrum (NCSC) has reported that multiple systems with port 5900 accessible from the internet have been compromised. NCSC notes that this vulnerability is particularly concerning because it can be exploited without any valid login credentials.
The exploit works by allowing a remote attacker to authenticate to a macOS system simply by naming an account. “Naming an account is the one thing the bug needs,” explains AI security firm Calif, adding that “it’s not much of a barrier.” In other words, as long as an attacker knows the username of an account on a vulnerable Mac with Screen Sharing enabled, they can gain access.
This is not the only recent vulnerability affecting screensharingd, the daemon responsible for managing Screen Sharing connections. Apple patched at least four issues in this component earlier this month, including three that have CVE identifiers and one more severe flaw that allowed unauthenticated attackers to gain remote code execution as root. This particular issue was silently addressed by Apple but could have been exploited to take over any macOS with Screen Sharing enabled.
According to security researcher osxreverser, approximately 40,000 internet-accessible macOS systems had Screen Sharing enabled in August, making them potentially exposed to attacks. It’s worth noting that this is not a zero-day exploit; the vulnerability was patched by Apple just over a week ago. However, it highlights the importance of keeping software up-to-date and being vigilant about potential exploits.
The fact that threat actors are already exploiting CVE-2026-65400 in real-world attacks serves as a reminder to users to be cautious when using Screen Sharing. It’s essential to understand the risks associated with this feature and take steps to minimize them, such as disabling it when not needed or using alternative solutions for remote access.
In practical terms, macOS users should ensure their systems are updated to the latest version of the operating system, which includes patches for CVE-2026-65400. It’s also crucial to review Screen Sharing settings and consider disabling the feature if it’s not essential to daily operations. By taking these precautions, users can help prevent potential attacks and maintain the security of their Macs.
Source: SecurityWeek — 2026-08-17