Hackers actively exploit macOS flaw giving full control, install Monero miner

Hackers actively exploit macOS flaw giving full control, install Monero miner

Dutch authorities have warned that attackers are actively exploiting a serious macOS vulnerability that allows remote attackers to gain complete control over affected systems, ArsTechnica reports.

Days earlier, the Dutch National Cyber Security Centre (NCSC) said it had already confirmed cases of the bug being used on several computers where port 5900 was exposed to the internet. In every incident, hackers obtained root access to compromised machines and then installed a Monero cryptocurrency miner.

The vulnerability is tracked as CVE-2026-65400. Apple patched it last week in update 26.6.1 for macOS Tahoe, Sequoia, and Sonoma. Its severity is rated 7.1 out of 10.

The bug stems from a flaw in the Screen Sharing feature, which allows remote viewing of the display and control of the keyboard and mouse. The root cause is an error in the "state management" mechanism — a system that tracks previous events, user interactions, and other parameters. Apple previously stated that CVE-2026-65400 "may" allow access without entering credentials.

A video demonstrating the vulnerability in action is available below.

According to NCSC, exploitation occurs precisely when port 5900 is open on the network. With Screen Sharing enabled, this port is automatically opened through the built-in macOS firewall. Routers and external firewalls typically block it unless the user has changed the settings. Experts advise keeping the port closed even when using the screen sharing feature, and for secure connections recommend using VPN or SSH tunneling.

Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate