Link CopyTwitterLinkedinWhatsapp
macOS Screen Sharing Flaw Lets Hackers Gain Root Access: Apple Users Need To Update Now

macOS Screen Sharing Flaw Lets Hackers Gain Root Access: Apple Users Need To Update Now

CVE-2026-65400 is a critical macOS Screen Sharing vulnerability that lets attackers bypass authentication and potentially gain root access. Apple has released security updates for affected Mac versions. Here is everything you should know about this and how you can protect your privacy.
[object Object]
Published: Aug 18, 2026, 01:29PM IST
Prefer us on
macOS Screen Sharing Flaw Lets Hackers Gain Root Access: Apple Users Need To Update Now
A critical vulnerability in Apple's macOS Screen Sharing feature is being actively exploited by hackers to gain root access to vulnerable Macs and install Monero cryptocurrency mining software. This flaw, tracked as CVE-2026-65400, allows attackers to bypass the normal authentication process and access Screen Sharing without valid credentials. Sounds scary? Right? But there is a way in which you can safeguard your data and your privacy.
The vulnerability is particularly concerning for Macs with Screen Sharing exposed to the internet through port 5900. Apple's security updates addressing the flaw were released on August 6, but security researchers and the Netherlands' National Cyber Security Centre have since confirmed exploitation in the wild.
About The Author
Aarohy Kapoor is a dynamic content producer and editor, known for creating high-impact, consumer-first content across diverse categories including technology, home decor, health & fitness, food, pet care, sports and everyday lifestyle essentials. With a strong editorial experience and an understanding of modern consumer behaviour, she specialises in product reviews, comparison articles, buying guides and deal-led content that simplify decision-making for readers. Her writing stands at the intersection of combining deep product analysis with relatable storytelling. Aarohy has a keen eye for detail, enabling her to break down complex specifications into easy, actionable information that helps readers choose smarter and shop better. Whether it is decoding the best tech gadgets, curating wellness essentials or highlighting everyday lifestyle upgrades, her work consistently focuses on value, clarity and authenticity across categories. Over the years, she has also played a pivotal role in shaping high-performing sales and deals content, mastering the art of blending editorial integrity with commercial relevance—an increasingly critical skill in today’s content-commerce ecosystem. But that is not all. She has always been a storyteller, which, till today, shapes the way she curates and edits the content. Beyond digital publishing, she is also a published book author. Her early work explored themes around food, culture and personal expression, along with interviewing the famous and the should-be famous personalities. These elements continue to influence her writing voice today subtly. When she is not decoding products or crafting compelling content, Aarohy embraces a more creative side of life and believes in striking off something or the other from her bucket list. She is a yoga enthusiast, an artist, an experimental cooking lover and an avid animal lover. She completely enjoys picking up new skills as an adult, from learning French professionally to picking up crochet just for fun; you will find her with something new every time.

Highlights

  • Hackers are actively exploiting a macOS Screen Sharing vulnerability to gain root access to vulnerable Macs.
  • The flaw can allow attackers to bypass Screen Sharing authentication without valid credentials.
  • Attacks have been observed on Macs with port 5900 exposed to the internet, with Monero miners installed after compromise.
  • Apple patched the vulnerability in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
  • Mac users should install the latest security update and disable Screen Sharing if they do not need the feature.

What Is The macOS Screen Sharing Flaw?
The vulnerability is identified as CVE-2026-65400 and affects the authentication process used by macOS Screen Sharing. Screen Sharing allows users to remotely view and even control a Mac from another device. This feature uses Apple’s implementation of the VNC-based Remote Framebuffer protocol and commonly operates through TCP port 5900.
This security issue means an attacker with network access to a vulnerable Screen Sharing service can potentially complete the authentication process without having valid credentials. This means that unless properly protected, your device can become a potential entry point for attackers.
Hackers Are Already Exploiting The macOS Vulnerability
This is not just an ordinary problem. The Netherlands' National Cyber Security Centre has confirmed active exploitation of CVE-2026-65400 against multiple systems where port 5900 was accessible from the internet. In the recently reported cases, the attackers were able to obtain root access and install Monero cryptocurrency miners on the compromised Macs. This attack is an example of cryptojacking, where hackers secretly use someone else's computing resources to mine cryptocurrency.
Once installed, cryptocurrency-mining malware can consume significant CPU resources, increase power consumption and potentially affect system performance. So, your device’s efficiency goes down.

Why Is This macOS Flaw So Dangerous?

The flaw becomes dangerous because of the authentication bypass. An attacker here does not need the Screen Sharing password first. The vulnerability here can allow the attacker to get through the authentication process without needing any credentials.
The issue becomes even more serious when the attacker gets root-level access. Root is the highest level of privilege on a Unix-based operating system such as macOS, giving an attacker far greater control over the compromised system. CISA also increased the vulnerability's severity rating from 7.1 to 9.8 out of 10, placing it in the critical category. The higher rating reflects the potential for remote exploitation without requiring prior privileges.

Which macOS Versions Are Affected?

Apple released security updates for the affected operating system branches on August 6. Here are the details:
macOS versionPatched version
macOS Tahoe26.6.1
macOS Sequoia15.7.9
macOS Sonoma14.8.9
Mac users who are working on earlier builds should install the latest security update as a priority. Apple’s security updates are designed to address the authentication issue in Screen Sharing, making it one of the most important updates for Mac users to install on priority.

Who Is Most At Risk?

It is important to understand that this vulnerability does not mean that every Mac connected to the internet can automatically be compromised. The concern is for systems where Screen Sharing is enabled, and port 5900 is exposed to the public internet. This is relevant for organisations, developers and other users who remotely access Max along with rented or remotely hosted Max systems. Security researchers have also identified a potentially large number of internet-exposed systems, highlighting why publicly accessible Screen Sharing services are a concern.

Does Changing Your Mac Password Fix The Problem?

No, this is not an issue which can be fixed by just changing your password because the problem is an authentication bypass. The recommended response is to install Apple's security update. If Screen Sharing is not required, disabling the feature provides another layer of protection.

How To Protect Your Mac

Mac users should take the following steps:

1. Update macOS

Open:
Apple menu → System Settings → General → Software Update
Install the latest security update available for your Mac.

2. Disable Screen Sharing If You Don't Need It

Go to:
System Settings → General → Sharing → Screen Sharing
Turn Screen Sharing off if you do not use remote access.

3. Check Port 5900 Exposure

If you use Screen Sharing, make sure TCP port 5900 is not unnecessarily exposed directly to the public internet. Organisations that require remote access should use appropriate network controls rather than leaving remote desktop services openly accessible.

What Is The Monero Mining Connection?

The confirmed attacks here offer an indication of what hackers are doing after gaining access to Macs. According to reports citing the Dutch NCSC, attackers exploited vulnerable Macs and subsequently installed Monero mining software. Monero is a privacy-focused cryptocurrency that is frequently targeted by cryptojacking campaigns because it can be mined using general-purpose computing hardware.
For victims, the immediate signs may include unusually high CPU usage, increased power consumption, fans running more frequently and unexplained system slowdowns. However, the cryptocurrency miner is only one of the things that can happen to you with the security bypass via screen sharing. Your system might also be used for other malicious purposes as well.

Should Mac Users Be Worried?

Yes, Mac users should be worried. But the risk largely lies in how Screen Sharing has been configured. The confirmed exploitation makes this vulnerability more serious than a routine security bug. However, users who keep macOS updated and do not expose Screen Sharing to the internet have substantially less exposure to this specific attack.
The most important thing is not to wait for symptoms. Update macOS now, particularly if you use Screen Sharing for remote access.

FAQs

What is CVE-2026-65400?
CVE-2026-65400 is a macOS Screen Sharing authentication vulnerability that can allow attackers to authenticate without valid credentials and potentially gain access to vulnerable systems.
Can hackers get root access through the macOS Screen Sharing flaw?
Yes. The Netherlands' National Cyber Security Centre reported active exploitation in which attackers gained root access to affected Macs and installed Monero mining software.
Is the macOS Screen Sharing vulnerability being actively exploited?
Yes. Active exploitation has been confirmed on systems with Screen Sharing exposed through port 5900 on the internet.
Which macOS versions have received the fix?
Apple released fixes in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Does changing the Screen Sharing password protect against CVE-2026-65400?
No. Since the vulnerability involves an authentication bypass, changing the password does not address the underlying flaw. Users should install the relevant macOS security update.
What should Mac users do right now?
Update macOS to the latest available version. Users who do not need Screen Sharing should also disable the feature and ensure that port 5900 is not unnecessarily exposed to the internet.
end of article