Key facts
- A critical macOS vulnerability, CVE-2026-65400, allows remote attackers to gain full control of Macs.
- The vulnerability is being actively exploited, with attackers accessing root privileges and installing Monero miners.
- The flaw is in the macOS screen sharing feature, which opens port 5900 when enabled.
- Apple released a patch for the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma.
- Security officials advise users to keep port 5900 closed, enable screen sharing only when needed, and turn it off afterward.
Dutch officials have issued a warning regarding a critical vulnerability in macOS that allows attackers to gain complete control over affected Macs. The flaw, tracked as CVE-2026-65400, is reportedly under active exploitation, with attackers observed gaining root access and installing Monero cryptocurrency miners on compromised systems, particularly when port 5900 is accessible from the internet.
