V-Help
← All news
Security

Critical macOS Screen Sharing Vulnerability Allows Remote Root Access

Critical macOS Screen Sharing Vulnerability Allows Remote Root Access

Photo: Tom's Hardware

Quick answer

Critical CVE-2026-65400 in macOS Screen Sharing allows attackers to bypass authentication and gain root access to devices.

Experts from the Dutch National Cyber Security Centre (NCSC-NL) have detected active exploitation of the CVE-2026-65400 vulnerability in macOS Screen Sharing to compromise Apple devices. Attacks target Macs with port 5900 exposed, through which attackers gain root access and install Monero cryptocurrency miners.

Apple released emergency patches on August 6 for macOS Tahoe, Sequoia, and Sonoma. However, on August 14, CISA raised the vulnerability’s severity to 9.8 on the CVSS scale. This is due to the attack requiring no privileges and enabling full system compromise, including data confidentiality, integrity, and availability. CISA previously rated the flaw at 7.1 but reassessed the attack vector after proof-of-concept exploits were published.

NCSC-NL warned that a proof-of-concept (PoC) exploit for the vulnerability is publicly available, and attacks have been observed on numerous unprotected systems. Technical details of the flaw were presented at the Black Hat conference, where researchers demonstrated the ability to bypass security mechanisms even on Apple M5 chips using AI.

Screen Sharing is a built-in macOS remote access feature based on VNC, disabled by default. The vulnerability allows attackers to authenticate without credentials. Users unable to install updates are advised to disable Screen Sharing in system settings.

This is the second Screen Sharing vulnerability patched in a month. The previous flaw (CVE-2026-43760) required valid credentials for exploitation, whereas the new vulnerability allows full authentication bypass.

Common questions

What is the CVE-2026-65400 vulnerability in macOS?
It is a flaw in Screen Sharing that allows attackers to bypass authentication and gain root access to Macs. Cybercriminals exploit it to install malware, such as cryptocurrency miners.
How can I protect against this vulnerability?
Install the latest macOS updates: Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9. If updates are unavailable, disable Screen Sharing in system settings.
Why did CISA raise the vulnerability’s severity to 9.8?
The agency revised the attack vector: exploitation no longer requires privileges, and the impact includes full system compromise. This makes the vulnerability critically dangerous and suitable for large-scale attacks.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: Tom's Hardware