Urgent Security Update: Apple Patches Critical macOS Screen Sharing Vulnerability Exploited for Monero Mining

September 8, 2026
Urgent Security Update: Apple Patches Critical macOS Screen Sharing Vulnerability Exploited for Monero Mining
  • First, apply the Apple update and verify whether Screen Sharing is needed; if not, disable it and avoid relying on password changes as a fix since the flaw lies in the authentication path itself.

  • In real-world incidents, attackers have gained root access on affected Macs and installed Monero miners, underscoring plausible damage but not a guaranteed outcome for every system.

  • The vulnerability, CVE-2026-65400, is an authentication flaw in macOS Screen Sharing that can allow attackers to log in without valid credentials, effectively bypassing the login check.

  • Exploitation requires a vulnerable macOS version with network reach to Screen Sharing, with particular risk when port 5900 is exposed to the Internet; attacks have targeted internet-facing 5900.

  • Apple patched the flaw on August 6, 2026, in macOS Sonoma 14.8.9, macOS Sequoia 15.7.9, and macOS Tahoe 26.6.1; users on older builds should update immediately if Screen Sharing is reachable over the network.

  • The fixed ranges are: Sonoma 14.0–14.8.8 updated to 14.8.9; Sequoia 15.0–15.7.8 updated to 15.7.9; Tahoe 26.0–26.6.0 updated to 26.6.1; users should confirm their version and apply the appropriate update.

  • If an immediate update isn’t possible, temporarily disable Screen Sharing and block direct public access to TCP port 5900 to reduce exposure.

Summary based on 1 source


Get a daily email with more Tech stories

Source

CVE-2026-65400: Update macOS Screen Sharing

More Stories