Critical macOS Screen Sharing Vulnerability Exploited by Hackers – Security Threat Alert

www.news4hackers.com-critical-macos-screen-sharing-vulnerability-exploited-by-hackers-security-threat-alert-critical-macos-screen-sharing-vulnerability-exploited-by-hackers-security-threat-alert

Threat actors are leveraging a recently addressed macOS security flaw to achieve unauthorized root access and deploy cryptocurrency mining software.

Vulnerability Overview

Recent macOS Screen Sharing Vulnerability Exploited in Attacks Threat actors are leveraging a recently addressed macOS security flaw to achieve unauthorized root access and deploy cryptocurrency mining software. The vulnerability, designated CVE-2026-65400, is a critical authentication flaw within the Screen Sharing feature that enables remote attackers to bypass credential requirements.

Apple’s Response

Apple addressed the issue on August 6 through updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Apple enhanced its authentication mechanisms to ensure proper validation of login credentials, according to internal documentation.

Active Exploitation

A week later, the Dutch National Cyber Security Centrum (NCSC) confirmed active exploitation of the flaw, citing reports of compromised systems with port 5900 exposed to the internet. Attackers have been using the vulnerability to gain elevated privileges and install Monero miners on affected devices.

Cybersecurity Firm Insights

A cybersecurity firm, Calif, highlighted that the flaw allows remote access by simply specifying an account name. The researchers emphasized that usernames are not confidential and are displayed on the login interface, making the barrier minimal.

According to internal documentation, Apple enhanced its authentication mechanisms to ensure proper validation of login credentials.

Additional Vulnerabilities

CVE-2026-65400 is not the only recent Screen Sharing vulnerability addressed by Apple. In late July, the company resolved at least four other issues within the Screen Sharing daemon, including three with assigned CVE identifiers. One unpublicized flaw, deemed the most severe, permitted unauthenticated remote code execution with root privileges.

Researcher’s Findings

A security researcher, osxreverser, noted that this flaw could be exploited to compromise any macOS system with Screen Sharing enabled if the attacker knew its IP address and had System Integrity Protection (SIP) disabled. The vulnerability did not require user interaction, allowing attackers to establish a reverse shell and execute root-level commands via the same connection.

osxreverser estimated that approximately 40,000 macOS systems with publicly accessible Screen Sharing were at risk.

Risk Mitigation

Additional vulnerabilities impacting Screen Sharing have been identified, including a separate flaw that allowed unauthorized access through misconfigured network settings. Security teams are advising users to apply patches promptly and disable Screen Sharing on systems not requiring the feature.

Security Recommendations

The exploitation of these vulnerabilities underscores the risks associated with outdated software and improperly configured services. Organizations are urged to monitor network traffic for suspicious activity on port 5900 and review system configurations to mitigate potential threats.



About Author

en_USEnglish