Collection

macOS Screen Sharing bug (CVE-2026-65400) exploited in the wild for root access

2 sources
Post cover image

Questions this post answers

What is CVE-2026-65400 and how does it let attackers get root access on a Mac?

CVE-2026-65400 is a macOS Screen Sharing vulnerability caused by a state management flaw that lets the authentication process be tricked into skipping the credential check entirely, granting root access without a password. Attackers exploit it by targeting Macs with port 5900 exposed to the internet, then drop Monero cryptominers on compromised machines. Apple rated it 7.1 out of 10 in severity. Track actively exploited macOS vulnerabilities like this one on daily.dev to patch before attackers strike.

Which macOS versions fix CVE-2026-65400 and when was it patched?

Apple fixed the Screen Sharing root access flaw on August 6 with updates to macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The Netherlands' National Cyber Security Centre reported active exploitation shortly after details were disclosed at Black Hat, so machines running earlier versions remain vulnerable until updated. Keep macOS patch timelines like this one handy on daily.dev when planning fleet updates.

How can I protect my Mac from the Screen Sharing root exploit if I can't update immediately?

Disable Screen Sharing in System Settings until the update can be applied. Exposing port 5900, the standard VNC/Screen Sharing port, to the internet on an unpatched Mac allows attackers to bypass authentication entirely and gain root access, after which they commonly install Monero cryptominers. daily.dev surfaces mitigation steps for active exploits like this one while patches roll out.

123 Impressions