Forgot your password?
typodupeerror
Desktops (Apple) OS X Security

Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation (arstechnica.com) 22

joshuark shares a report from Ars Technica: Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation. "The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet," the Netherlands National Cyber Security Centrum warned earlier this week. "In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed."

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the "state management," which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause. A video of the exploit in action can be found here. Details of CVE-2026-65400 became public at last week's Black Hat security conference. Apple said last week that CVE-2026-65400 "may" allow an attacker without credentials to gain access to a Mac. It's unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.

As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren't within the capabilities of most users. The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Of course, installing last week's security update is also a must. Sharing is not caring.

Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation

Comments Filter:
  • Port 5900.

    Simples :-)

    Await onslaught....

    • Screen sharing is turned off by default. At least it is on the M5 Macbook air that I just bought my wife (she's a Mac addict....don't ask...hehe). I just checked.

      • Screen sharing is turned off by default. At least it is on the M5 Macbook air that I just bought my wife (she's a Mac addict....don't ask...hehe). I just checked.

        Screen Sharing has been off by default for as long as I've used macOS / OS X.

        But, frankly, VNC has been known to be horribly insecure for many, many years - Apple really shouldn't be using it at all. Even the major Linux distros appear to be moving away from it and over to (x)RDP... which is also more performant than VNC, for that matter

  • With all the notarization requirements and then they get hit with a flaw anyway. With all the new Mac users thanks to the Macbook Neo expect more scrutiny of the Mac.
    • by pahles ( 701275 )
      This is a OS flaw (or at least a flaw in software that came with the OS install), what does notarization have to do with it?
      • by drnb ( 2434720 )

        This is a OS flaw (or at least a flaw in software that came with the OS install), what does notarization have to do with it?

        The software that came with macOS includes a firewall. The user just needs to enable it.

      • by xack ( 5304745 )
        It's a false sense of security, Windows and Linux users are more trained on possible risks. Plus Apple making devs go through all the hoops while letting their guard down internally.
  • Just another example why you should keep your system up to date.
  • And ONLY for this vuln.

    This patch came just nine days after apple published a record breaking patch set of more than a hundred security patches (depending of OS version).

    Apple took the PR egg on face, and the extra load on the update servers, to emit a patch for just that security vuln, instead of just waiting for the next regular patch (expected right after MscOS 27 is emitted, on Oct~Nov this year)

    I did update. I did recommended people to update.

    If people is too sttuborn to update, what can you do?

    • by Slayer ( 6656 )

      If people is too sttuborn to update, what can you do?

      When they get hit, they will blame you for the bug, and for pestering them with this booooring computer topic. They will also claim to have cooked the perfect spaghetti aglio olio e peperoncino, to which you will be kindly invited between 6 and 8 on a specific date next week. Sorry, they are fully booked on all other days, and there is a TV show they can't miss after 8 on that day. After the spaghetti they will escort you to their now dead Mac ...

    • by Bahbus ( 1180627 )

      Apple took the PR egg on face

      No, they really didn't.

      extra load on the update servers

      Not really.

      If people is too sttuborn to update, what can you do?

      Stop giving (non-enterprise) users a choice over security updates.

Where it is a duty to worship the sun it is pretty sure to be a crime to examine the laws of heat. -- Christopher Morley

Working...