Vulnerability giving attackers full control of Macs is under active exploitation
Screen-sharing bug lets remote hackers log in without a password.

Screen-sharing bug lets remote hackers log in without a password.
The short version
- Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.
- “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week.
- “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.” A video of the exploit in action can be found here .
What happened
Details of CVE-2026-65400 became public at last week’s Black Hat security conference. Apple said last week that CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac.
Why it matters
It’s unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.
Summary by Nerd News Network. Read the full article at Ars Technica via the links above and below.
