Aug 15, 2026
ManyPress

Advertisement

Technology

Dutch authorities report that a macOS screen sharing flaw is being used to gain root access and install cryptocurrency miners.

ManyPress

ManyPress

ManyPress Editorial

2 min readSource:Ars Technica
High-severity macOS vulnerability under active exploitation

Key facts

  • The NCSC observed active exploitation on systems where port 5900 was accessible from the internet.
  • Attackers are using the exploit to gain root access and install Monero crypto miners.
  • The vulnerability, CVE-2026-65400, stems from a state management bug in the macOS screen sharing capability.
  • Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week.
  • The vulnerability has a severity rating of 7.1 out of 10.

The Netherlands National Cyber Security Centrum (NCSC) has issued a warning regarding a high-severity vulnerability in macOS that is currently being exploited. Attackers are targeting systems with port 5900 exposed to the internet to gain root access and deploy Monero crypto miners.

By the numbers

7.1
severity rating of CVE-2026-65400
5900
port number targeted by attackers

Vulnerability details and impact

Tracked as CVE-2026-65400, the vulnerability carries a severity rating of 7.1 out of 10. It originates from a state management flaw within the macOS screen sharing feature, which can allow an unauthorized remote party to view a screen and control a device's keyboard and mouse.

Patch availability

Apple released a patch for the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma. While Apple stated the flaw 'may' allow an attacker without credentials to access a Mac, details regarding the exploit were publicly disclosed during the Black Hat security conference.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by Ars Technica.

Technology