News: 0184978502

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation (arstechnica.com)

(Saturday August 15, 2026 @11:00AM (BeauHD) from the PSA dept.)


[1]joshuark shares a report from Ars Technica:

> Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is [2]under active exploitation . "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet," the Netherlands National Cyber Security Centrum [3]warned earlier this week. "In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."

>

> The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the "state management," which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found [4]here . Details of CVE-2026-65400 [5]became public at last week's Black Hat security conference. Apple said last week that CVE-2026-65400 "may" allow an attacker without credentials to gain access to a Mac. It's unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.

>

> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren't within the capabilities of most users. The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week's security update is also a must. Sharing is not caring.



[1] https://slashdot.org/~joshuark

[2] https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/

[3] https://advisories.ncsc.nl/2026/ncsc-2026-0280.html

[4] https://xcancel.com/calif_io/status/2086022794840793454

[5] https://blog.calif.io/p/no-country-for-old-passwords



Simply close (Score:2)

by Finallyjoined!!! ( 1158431 )

Port 5900.

Simples :-)

Await onslaught....

Wait... (Score:1)

by guygo ( 894298 )

I thought "Apple computers don't get viruses".

Re: (Score:3)

by pahles ( 701275 )

What do viruses have to do with this issue?

Macs are security theater (Score:2)

by xack ( 5304745 )

With all the notarization requirements and then they get hit with a flaw anyway. With all the new Mac users thanks to the Macbook Neo expect more scrutiny of the Mac.

Re: (Score:3)

by pahles ( 701275 )

This is a OS flaw (or at least a flaw in software that came with the OS install), what does notarization have to do with it?

The bugs you have to avoid are the ones that give the user not only
the inclination to get on a plane, but also the time.
-- Kay Bostic