Dangerous Mac flaw allows hackers to take over screens

Macs running older versions of Sonoma, Sequoia, or Tahoe could be at risk

A dangerous macOS Screen Sharing flaw could let attackers take control of vulnerable Macs without valid credentials | ©Image Credit: Unsplash / Elise Bouet
A dangerous macOS Screen Sharing flaw could let attackers take control of vulnerable Macs without valid credentials | ©Image Credit: Unsplash / Elise Bouet

If you own a Mac, you might want to check for an update as soon as possible. Apple has fixed a serious vulnerability in its Screen Sharing feature that can let attackers on the same network authenticate to a Mac without valid credentials. The flaw is now being actively exploited, according to the Netherlands National Cyber Security Centre, which says attackers have already used it to gain root access and install Monero cryptocurrency miners.

The scary part is not just someone watching your screen

Screen Sharing is designed to let you remotely access and control a Mac. That’s useful when you’re troubleshooting your computer from another room or helping someone fix a problem. But when the authentication protecting that feature breaks, the same functionality can become a giant welcome mat for attackers.

Apple says the vulnerability, tracked as CVE-2026-65400, could allow an attacker on the network to access Screen Sharing without valid credentials. In practical terms, that can mean far more than someone seeing what you’re doing. An attacker who gains control could potentially interact with your Mac much like someone sitting in front of it: opening applications, accessing files, viewing private information, and controlling the keyboard and mouse. That’s the nightmare scenario.

Hackers are already exploiting it

When Apple initially released the security updates, it said there was no evidence the vulnerability was being exploited in the wild. But that changed. The Netherlands NCSC says it received reports that the vulnerability was being actively abused on systems with port 5900 accessible from the internet.

In the reported incidents, attackers obtained root access and installed a Monero crypto miner. For anyone unfamiliar with the crypto-mining playbook, the idea is basically criminals hijacking your computer’s processing power to mine cryptocurrency for themselves. Your Mac pays the electricity and performance bill while the attacker gets the coins.

Thousands of Macs may have been exposed

The vulnerability becomes particularly concerning because Screen Sharing can expose port 5900 when the feature is enabled. One researcher reportedly found roughly 40,000 Macs with Screen Sharing enabled and reachable from the internet. That doesn’t mean 40,000 Macs were hacked. It does, however, show how many potentially exposed systems existed when researchers started looking.

Apple already patched the vulnerability

Apple has released fixes for its three most recent macOS versions: macOS Sonoma 14.8.9, macOS Sequoia 15.7.9, and macOS Tahoe 26.6.1. The company initially described the releases simply as important security updates before providing more details about the Screen Sharing vulnerability.

Security researchers later reverse-engineered Apple’s patch and discovered just how serious the underlying issue was.

Here’s what Mac owners should do

First, you should update your Mac if you haven’t already. Go to System Settings → General → Software Update and check whether one of the patched versions is available for your machine.

Then, take a look at Screen Sharing. Go to System Settings → General → Sharing and check whether Screen Sharing is enabled. If you don’t actively use it, turn it off. If you do need it, keep it enabled only when necessary and make sure you disable it when you are finished.

It may not seem like much, but this is one of those wonderfully boring cybersecurity habits that can save you from a spectacularly annoying afternoon.

Sources: 9to5 Mac, Mashable, CNET