Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Vulnerability Giving Attackers Full Control of Macs: A Growing Threat Under Active Exploitation


Mac users are advised to take immediate action to protect themselves from a critical vulnerability in macOS that allows attackers to gain full control over Macs under active exploitation. By blocking screen sharing, enabling it only when needed, and staying up-to-date with the latest security patches, users can significantly reduce the risk of falling victim to this exploit.

  • Apple has acknowledged a critical vulnerability in macOS (CVE-2026-65400) that allows attackers to gain full control over Macs.
  • The vulnerability stems from a bug in the macOS screen sharing capability, which allows remote access to the screen, keyboard, and mouse.
  • Port 5900 must be closed and screen sharing must be turned off when not in use to prevent exploitation.
  • Security experts recommend using a VPN or SSH tunneling instead of screen sharing.
  • Users should keep their Macs up-to-date with the latest security patches to reduce the risk of falling victim to this exploit.



  • Recently, a critical vulnerability in macOS has been detected, allowing attackers to gain full control over Macs under active exploitation. The vulnerability, tracked as CVE-2026-65400, has been reported by Dutch officials, who have warned that active abuse of this vulnerability has been observed on multiple systems where port 5900 was accessible from the internet.



    According to the Netherlands National Cyber Security Centrum (NCSC), the vulnerability stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. The "state management" flaw in this capability allows a remote party to view and control the screen, keyboard, and mouse without needing to authenticate or provide any credentials.



    The vulnerability was discovered and disclosed at last week's Black Hat security conference, where it was revealed that the bug in the screen sharing capability allows an attacker without credentials to gain access to a Mac. Apple has acknowledged this vulnerability and has released a patch for macOS Tahoe, Sequoia, and Sonoma.



    According to the NCSC, the vulnerability is being exploited when port 5900 is exposed to the internet. When screen sharing is turned on, the macOS firewall opens the port, which can be easily accessed by attackers if it is not properly secured. Routers and dedicated firewalls generally block this port unless configured to override that setting.



    Security experts generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. However, this requires actions that may not be within the capabilities of most users.



    The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing.



    Currently, there are no indications that exploits are being used to install anything other than Monero miners, which surreptitiously harness a Mac's resources to perform mathematical operations that generate cryptocurrency for the attacker. However, a bigger risk is that attackers might exploit the vulnerability to install malware that steals credentials or performs other nefarious activities.



    It is essential for Mac users to take immediate action to protect themselves from this vulnerability. By following the safest practices outlined above, users can significantly reduce the risk of falling victim to this exploit.



    The vulnerability highlights the importance of staying up-to-date with the latest security patches and being mindful of potential security risks associated with common features like screen sharing. As technology continues to evolve, it is crucial that users are aware of the potential threats and take proactive steps to protect themselves.





    Related Information:
  • https://www.ethicalhackingnews.com/articles/Vulnerability-Giving-Attackers-Full-Control-of-Macs-A-Growing-Threat-Under-Active-Exploitation-ehn.shtml

  • https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-65400

  • https://www.cvedetails.com/cve/CVE-2026-65400/


  • Published: Sat Aug 15 16:27:44 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us