MacOS Screen Sharing Flaw

Overview

The Netherlands’ National Cyber Security Centre (NCSC) has issued a warning about active exploitation of a macOS authentication bypass vulnerability in the built‑in Screen Sharing feature. The flaw, tracked as CVE‑2026‑65400, allows attackers to gain access to macOS systems without valid credentials. Apple patched the issue on August 6, 2026, but systems that remain unpatched are being targeted in the wild.

Vulnerability Details

  • Screen Sharing flaw: Uses the VNC protocol over TCP port 5900.
  • Impact: Attackers can remotely open applications, access files, change security settings, and gain root privileges.
  • Exploit activity: Public exploit code has been released, and attackers are scanning for exposed port 5900 instances.
  • Observed attacks: NCSC confirmed cases where attackers obtained root access and deployed a Monero cryptocurrency miner.

Affected Versions & Fixes

Apple addressed CVE‑2026‑65400 in the following releases:

  • macOS Tahoe 26.6.1
  • macOS Sequoia 15.7.9
  • macOS Sonoma 14.8.9

These updates improve state management mechanisms to enforce proper credential validation and block rogue authentication attempts.

Security Implications

  • Root access: Once exploited, attackers can fully control the system.
  • Cryptocurrency mining: Monero miners consume CPU resources, degrade performance, and increase energy costs.
  • Potential expansion: While current reports focus on mining, attackers could extend operations to data theft or lateral movement.

Defensive Guidance

macOS users should:

  • Update immediately: Apply the latest patches listed above.
  • Disable Screen Sharing: Navigate to System Settings → General → Sharing → Screen Sharing if the feature is not required.
  • Restrict network exposure: Ensure port 5900 is not accessible from the internet.
  • Monitor for miners: Watch for unusual CPU usage or unauthorized processes.

Expert in the Cloud Insight

This incident highlights how remote desktop features can become high‑value targets when exposed to the internet. The combination of a credential bypass and cryptocurrency mining payload shows attackers are quick to monetize vulnerabilities. For defenders, the lesson is clear: patch fast, disable unnecessary services, and monitor for resource hijacking.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.