A critical cybersecurity issue has emerged as a new macOS vulnerability allows remote attackers to gain full control of affected computers without requiring passwords. According to a report by Ars Technica, the security flaw is currently under active exploitation in the wild. Consequently, security experts advise users to update their systems immediately to prevent unauthorized access.
The security flaw, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. Specifically, the issue stems from a bug in the screen sharing capability of the operating system. This flaw allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on.
Details of the macOS Vulnerability
The underlying cause of the security issue is a flaw in the state management of the system. This component keeps track of preceding events, user interactions, variables, and other system states. Security firm Bynario reported the flaw to Apple, which subsequently released the necessary updates.
Active Exploitation and Impact
Dutch officials from the National Cyber Security Centrum (NCSC) warned that active abuse of this flaw has been observed on multiple systems. Specifically, these attacks occurred on machines where port 5900 was accessible from the internet. In all documented cases, attackers accessed root privileges and installed a Monero cryptocurrency miner.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet.”
Netherlands National Cyber Security Centrum
Currently, there are no indications that the exploit is being used to install malware other than these cryptocurrency miners. However, a larger risk remains that attackers could use the access to steal credentials or perform other activities on affected computers.
Mitigation and Safety Measures
To protect against this macOS vulnerability, users should adjust their network settings. When screen sharing is enabled, the macOS firewall automatically opens port 5900. Although routers and dedicated firewalls generally block this port, manual configurations can sometimes override these protections. Therefore, security practitioners advise users to keep the port closed and use a VPN or SSH tunneling for remote access.
The safest practice for users is to disable screen sharing entirely when it is not actively needed. Users can toggle this feature by accessing System Settings, selecting General, clicking Sharing, and switching off Screen Sharing. Additionally, installing the latest security updates remains the most effective defense against this threat.
Future Security Outlook
The details of the macOS vulnerability were publicly disclosed at the Black Hat security conference. Apple stated that the flaw may allow an attacker without credentials to gain access to a Mac. As cyber threats evolve, maintaining updated software on all devices is essential for strong protection.





