Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation

Critical macOS Vulnerability Under Active Exploitation Allows Remote Control

Critical macOS Vulnerability Under Active Exploitation Allows Remote Control

A high-severity macOS vulnerability (CVE-2026-65400) that enables attackers to execute malicious code and gain full system control is currently being actively exploited. Dutch cybersecurity authorities warn that the flaw, which stems from a bug in macOS screen sharing capabilities, has been observed in multiple systems where port 5900 was exposed to the internet. Attackers exploited this vulnerability to access root privileges and deploy Monero crypto miners. Apple patched the issue last week for macOS versions Tahoe, Sequoia, and Sonoma, but the NCSC emphasizes that the vulnerability remains a significant risk if screen sharing is enabled without proper firewall configuration. Security experts advise users to block port 5900 unless absolutely necessary, preferring secure alternatives like VPNs or SSH tunnels. The flaw, which received a severity rating of 7.1 out of 10, highlights ongoing challenges in macOS security despite its reputation for robustness. Apple’s cautious disclosure language regarding potential credentialless access has sparked debate among security professionals, who note that the vulnerability underscores systemic weaknesses rather than isolated incidents.

Leave a Reply

Your email address will not be published. Required fields are marked *