The Dutch National Cyber Security Centre has confirmed active exploitation of a critical authentication vulnerability in macOS Screen Sharing, urging users to update their systems immediately to prevent compromise.
Key Points
- The vulnerability, tracked as CVE-2026-65400, carries a critical CVSS score of 9.8 and allows unauthorized network access without valid credentials.
- Apple released patches for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address the flaw discovered by researcher Alfredo Pesoli.
- Attackers are actively targeting systems with port 5900 exposed to the internet to gain root access and install Monero cryptocurrency miners.
- Security firm Calif reported that the logic-based flaw is simple to exploit, with functional attack code created in just four hours using AI tools.
- Experts recommend disabling Screen Sharing in system settings if immediate software updates are not possible to mitigate the risk of unauthorized remote access.