Mac Screen Sharing Flaw Hits Live Exploitation On Exposed Port 5900
Ars Technica reported that CVE-2026-65400, a macOS Screen Sharing vulnerability patched by Apple last week, is now being exploited on systems with port 5900 exposed to the Internet. Dutch cyber officials observed root access and Monero miners on affected Macs, making patching and Screen Sharing exposure checks the immediate remediation path.

A patched macOS Screen Sharing flaw has moved from conference disclosure to live exploitation on Internet-exposed Macs, Ars Technica reported, turning a remote-access feature into an immediate patch and firewall issue for operators that leave port 5900 reachable online.
The vulnerability is tracked as CVE-2026-65400 and carries a 7.1 severity score.
Apple released fixes last week for macOS Tahoe, Sequoia and Sonoma after researchers disclosed details at the Black Hat security conference.
Port 5900 Exposure Defines The Attack Surface
The Netherlands National Cyber Security Centrum warned that active abuse had been observed on multiple systems where port 5900 was accessible from the Internet.
In those cases, root access had been obtained and a Monero cryptocurrency miner had been installed.
Screen Sharing lets a remote party view a Mac's screen and control the keyboard and mouse while the machine is running.
The bug sits in the feature's state management, the part of the system that tracks preceding events, user interactions, variables and other operating states.
Apple's advisory described the flaw as one that may allow an unauthenticated attacker to gain access to a Mac.
Routers or dedicated firewalls may still block inbound Screen Sharing traffic unless an administrator has exposed it.
Patch Status Does Not Remove Configuration Risk
Apple's update addresses the software flaw.
Network exposure remains a separate configuration issue when Screen Sharing is left on and rules forward or permit VNC traffic from the public Internet.
Security practitioners generally advise keeping direct VNC access closed and using a VPN or SSH tunneling when remote screen access is needed.
For users without those workflows, the safer operating pattern is to leave Screen Sharing disabled, enable it only for a specific session and turn it off when that session ends.
The current exploitation activity has been tied to Monero miners rather than credential theft or broader malware deployment.
That limits the observed payload, not the access level: root control gives attackers room to install more damaging tools if the same exposure remains open.
Mac operators now have two verifiable remediation steps: install Apple's latest macOS security updates and confirm that Screen Sharing is not exposed directly to the Internet.




















