Photo by Polina Tankilevitch via Pexels

macOS Screen Sharing Flaw Is Being Exploited Right Now

4 Min Read

If you own a Mac and have screen sharing enabled, this is not a drill. A high-severity security vulnerability in macOS is currently being actively exploited in the wild, with attackers using it to gain complete root access to affected machines and quietly install cryptocurrency mining software. Dutch cybersecurity officials confirmed the threat earlier this week, noting that multiple systems with port 5900 exposed to the internet had already been compromised.

What the Vulnerability Actually Does

The flaw, tracked as CVE-2026-65400, lives inside macOS’s screen sharing functionality, the built-in feature that lets a remote user view your display and control your keyboard and mouse. The root cause is a bug in state management, the underlying system that tracks user interactions, session variables, and ongoing processes. When this logic breaks down, an attacker can slip through the cracks and execute arbitrary malicious code without needing physical access to your machine.

With a severity score of 7.1 out of 10, this is not a theoretical edge case. It is a concrete, weaponized attack path that bad actors are using right now. The Netherlands National Cyber Security Centrum confirmed that on every compromised system they reviewed, root access had been achieved and a Monero crypto miner had been planted. That means attackers are silently stealing your computing power and electricity to generate cryptocurrency for themselves.

Who Is at Risk and How Serious Is This

The vulnerability affects macOS Tahoe, Sequoia, and Sonoma, which together represent the vast majority of active Mac users worldwide. Apple shipped a patch last week, but the window between disclosure and patching is exactly when attackers move fast, and they clearly have.

The specific attack vector here is port 5900, the default port used by VNC-based screen sharing on macOS. Any machine with screen sharing turned on and that port reachable from the internet is a potential target. This includes home users who enabled screen sharing for convenience, small businesses running remote desktop setups, and IT teams managing fleets of Macs without a firewall blocking external VNC access.

Crypto miners are the payload this time, but the same root access could just as easily be used to steal files, install ransomware, or create a persistent backdoor for future attacks.

What You Should Do Before Your Next Purchase Decision

First, update your Mac immediately. Go to System Settings and install the latest macOS security update. Second, disable screen sharing entirely if you do not actively need it, and if you do, make sure port 5900 is not exposed to the public internet.

For anyone currently evaluating a Mac purchase or considering upgrading their home or business setup, this incident is a reminder that security patch cadence and network configuration matter as much as hardware specs. Macs carry a strong security reputation, but that reputation depends on staying updated and making smart network choices. When comparing devices or planning a new tech purchase, factor in how quickly a vendor responds to critical threats because Apple’s fast patch here, while necessary, came after active exploitation had already begun.

Share This Article