A two-week-old Mac fix is already failing against live attacks

Dutch cyber agency confirms live attacks on the Mac Screen Sharing bug Apple patched this month, with Monero miners showing up on exposed systems.

AppleThreat Staff
2 Min Read

Macs that keep Screen Sharing switched on are showing up in Dutch government reports with mining software they never asked for, weeks after Apple shipped a fix for the feature.

The Dutch National Cyber Security Centre (NCSC-NL) said it received reports of active abuse of CVE-2026-65400, an authentication flaw rated 9.8 out of 10 that lets someone on the network sign in to Screen Sharing without credentials. In the cases it documented, whoever broke in walked away with root control and left a Monero miner running.

Apple’s August 6 release for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 closed the issue with stricter state handling during sign-in, and credited researcher Alfredo Pesoli of Bynario.

The reported intrusions centered on machines where port 5900, the port Screen Sharing answers on, sat open to the internet. The agency offered no timeline for when the attacks began, no victim count, and no word on whether the bug was ever abused before the patch existed.

During the previous update cycle, Apple removed two more Screen Sharing defects from the same stretch of code. A researcher who posts as @osxreverser described one of them as reachable before authentication ever happens, needing only a remote machine’s address to trigger. Security firm Calif examined the pair and concluded the flaws are plain logic defects, free of the memory-corruption stunts and timing games that usually gate such attacks. Its own automated tooling, the company added, turned both into working exploits in roughly four hours. For Mac owners, the safest move is to install the update immediately. When that is not possible, disabling Screen Sharing under General, Sharing eliminates the risk surface, and exposing port 5900 to the internet is asking for trouble.

Share This Article