<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq" -->

---
title: Vulnerability giving attackers full control of Macs is...
description: A high-severity macOS vulnerability, CVE-2026-65400, in the screen sharing feature is being actively exploited to gain root access without credentials. Dutch...
canonical: https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Vulnerability giving attackers full control of Macs is under active exploitation | daily.dev
og:description: A high-severity macOS vulnerability, CVE-2026-65400, in the screen sharing feature is being actively exploited to gain root access without credentials. Dutch...
og:url: https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq
og:image: https://api.daily.dev/og/posts/ra1DBGDkq.png
og:image:alt: Vulnerability giving attackers full control of Macs is under active exploitation
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Vulnerability giving attackers full control of Macs is under active exploitation

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 0 upvotes · 0 comments

## Summary

A high-severity macOS vulnerability, CVE-2026-65400, in the screen sharing feature is being actively exploited to gain root access without credentials. Dutch cybersecurity officials (NCSC) reported active abuse on systems with port 5900 exposed to the internet, with attackers deploying Monero crypto miners after gaining root. Apple patched the flaw last week for macOS Tahoe, Sequoia, and Sonoma, rated 7.1/10 severity, stemming from a state management bug in screen sharing. Details became public at Black Hat security conference.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation>

## Questions this post answers

### What is CVE-2026-65400 and how does it affect macOS screen sharing?

CVE-2026-65400 is a macOS vulnerability in the screen sharing feature that allows a remote attacker to gain root access without credentials, due to a flaw in state management tracking system events and variables. It carries a severity rating of 7.1 out of 10 and affects macOS Tahoe, Sequoia, and Sonoma. Apple patched it, and details were disclosed publicly at the Black Hat security conference.

_Mac admins tracking active exploits like this rely on daily.dev to stay ahead of patch cycles._

### Is the macOS screen sharing vulnerability CVE-2026-65400 being actively exploited?

Yes, the Netherlands National Cyber Security Centrum confirmed active abuse on multiple systems where port 5900 was exposed to the internet. In every observed case, attackers gained root access and installed a Monero crypto miner on the compromised machine.

_Security teams monitoring active exploitation reports like this follow the space on daily.dev._

### Which macOS versions received a patch for CVE-2026-65400?

Apple released patches for macOS Tahoe, Sequoia, and Sonoma to fix CVE-2026-65400, a screen sharing vulnerability that could let attackers execute malicious code and gain root access without a password. The patches shipped shortly before the flaw's public disclosure at Black Hat.

_Developers keeping macOS fleets patched track advisories like this through daily.dev._

## Similar posts on daily.dev

- [Apple's MacOS Security Gap Lets Users Disable Security Tools](https://daily.dev/posts/apple-s-macos-security-gap-lets-users-disable-security-tools-jn2emr9jx) · Dark Reading · 0 upvotes · 0 comments
- [cPanel flaw exposes enterprises to hosting supply-chain risks](https://daily.dev/posts/cpanel-flaw-exposes-enterprises-to-hosting-supply-chain-risks-dd2mlbkvf) · CSO Online · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#apple](https://daily.dev/tags/apple), [#mac](https://daily.dev/tags/mac)

[View this post on daily.dev](https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Vulnerability giving attackers full control of Macs is under active exploitation","url":"https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq"},"datePublished":"2026-08-14T19:32:23.467Z","dateModified":"2026-08-21T15:51:18.135Z","description":"A high-severity macOS vulnerability, CVE-2026-65400, in the screen sharing feature is being actively exploited to gain root access without credentials. Dutch...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/98487e8d4635263dce3c5bcf2cbb8f53?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/98487e8d4635263dce3c5bcf2cbb8f53?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,apple,mac","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Vulnerability giving attackers full control of Macs is under active exploitation"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation-ra1dbgdkq#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-65400 and how does it affect macOS screen sharing?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-65400 is a macOS vulnerability in the screen sharing feature that allows a remote attacker to gain root access without credentials, due to a flaw in state management tracking system events and variables. It carries a severity rating of 7.1 out of 10 and affects macOS Tahoe, Sequoia, and Sonoma. Apple patched it, and details were disclosed publicly at the Black Hat security conference. Mac admins tracking active exploits like this rely on daily.dev to stay ahead of patch cycles."}},{"@type":"Question","name":"Is the macOS screen sharing vulnerability CVE-2026-65400 being actively exploited?","acceptedAnswer":{"@type":"Answer","text":"Yes, the Netherlands National Cyber Security Centrum confirmed active abuse on multiple systems where port 5900 was exposed to the internet. In every observed case, attackers gained root access and installed a Monero crypto miner on the compromised machine. Security teams monitoring active exploitation reports like this follow the space on daily.dev."}},{"@type":"Question","name":"Which macOS versions received a patch for CVE-2026-65400?","acceptedAnswer":{"@type":"Answer","text":"Apple released patches for macOS Tahoe, Sequoia, and Sonoma to fix CVE-2026-65400, a screen sharing vulnerability that could let attackers execute malicious code and gain root access without a password. The patches shipped shortly before the flaw's public disclosure at Black Hat. Developers keeping macOS fleets patched track advisories like this through daily.dev."}}]}
```

