ELSEIF
Your brief EB
187 stories from 105 feeds 341 clusters Refreshed 2 minutes ago next pull 15:22

SECURITY Signal 418

Apple patches actively exploited macOS Screen Sharing bug granting remote root access via authentication bypass

A critical flaw in macOS Screen Sharing, actively exploited for Monero cryptojacking, allows attackers to bypass authentication and gain root access on exposed systems.

WHY IT MATTERS

This vulnerability exposes unpatched Macs with Screen Sharing enabled to remote compromise, even without user interaction. The severity upgrade to 9.8 reflects its potential for automated, large-scale attacks, making immediate patching essential for security teams.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

CVE-2026-65400 enables authentication bypass in macOS Screen Sharing, granting attackers root access without credentials.

02

CISA raised the CVSS score from 7.1 to 9.8 after confirming the attack is automatable and requires no privileges.

03

Active exploitation has been observed, with attackers installing Monero miners on exposed systems via port 5900.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

The flaw affects macOS Screen Sharing, Apple’s built-in VNC-based remote desktop service. Attackers exploit an authentication bypass to gain root-level access on systems where port 5900 is exposed to the internet. The Dutch National Cyber Security Centre (NCSC-NL) reported active exploitation, with compromised machines used for Monero cryptocurrency mining. Apple’s patch, released in an out-of-band update, addresses the issue by improving state management during authentication.

CISA’s severity reassessment highlights the flaw’s critical nature. Initially scored at 7.1, the agency later revised the CVSS score to 9.8, reflecting a shift in understanding: the attack requires no privileges and results in full system compromise. The change also reclassified the exploit as automatable, aligning with observed large-scale attacks. Despite this, the flaw remains absent from CISA’s Known Exploited Vulnerabilities catalog, creating potential confusion for prioritization.

The vulnerability’s impact is limited to systems with Screen Sharing enabled and port 5900 exposed. While the service is disabled by default, organizations or users who enable it for remote access are at risk. The patch covers multiple macOS versions, but the presence of public proof-of-concept code and active exploitation underscores the urgency of applying updates. Temporary mitigation includes disabling Screen Sharing until the patch is deployed.

This incident follows a similar Screen Sharing vulnerability patched in late July, suggesting recurring issues in the service’s authentication mechanisms. The rapid succession of patches indicates Apple’s focus on addressing high-risk flaws, but the active exploitation of this bug demonstrates the need for proactive monitoring of exposed services. Security teams should audit macOS deployments for unnecessary remote access tools and ensure timely patch management.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Tomshardware Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks Open ↗