SECURITY Signal 474
macOS screen sharing flaw under active exploitation grants attackers root access without credentials
A high-severity macOS screen-sharing vulnerability tracked as CVE-2026-65400 is under active exploitation, allowing remote attackers to gain root access without a password on systems with port 5900 exposed to the internet.
Attackers are currently using this flaw to install Monero crypto miners, but the root access granted by the vulnerability could easily be used for credential theft or more destructive malware. Apple has released patches for macOS Tahoe, Sequoia, and Sonoma, but systems with internet-exposed port 5900 remain at risk if unpatched.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
A state management flaw in macOS screen sharing allows unauthenticated remote attackers to execute code and gain root access.
The Netherlands National Cyber Security Centrum reports active exploitation where port 5900 is accessible, resulting in Monero miner installations.
Apple patched the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma, advising users to install the update and block port 5900.
THE CLUSTER
↗