started · updated
Apple patches critical macOS Screen Sharing vulnerability
Apple has released emergency security updates to address a critical vulnerability, identified as CVE-2026-65400, affecting the Screen Sharing service on macOS Sequoia, Sonoma, and Tahoe. The flaw, which carries a severity score of 9.8 out of 10, allows remote attackers to bypass authentication and gain full access to a Mac without a password or user interaction.
The National Cyber Security Centre of the Netherlands (NCSC-NL) has reported that the vulnerability is being actively exploited in the wild. Attackers targeting machines with the Screen Sharing service exposed to the internet have successfully obtained root privileges to install Monero cryptocurrency mining Trojans.
Security researcher Alfredo Pesoli, CEO of Bynario, identified the flaw using automated detection systems. Users running affected versions of macOS are urged to update immediately to the latest security patches to prevent unauthorized remote access and system compromise.
Entities
Alfredo Pesoli · Apple · Bynario · CISA · NCSC-NL · National Cyber Security Centre of the Netherlands · macOS
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] Attackers have used the exploit to install cryptocurrency mining Trojans. pisapapeles.net · wwwhatsnew.com · www.datasecuritybreach.fr
- [● 3 SOURCES] The National Cyber Security Centre of the Netherlands (NCSC-NL) reported real-world attacks exploiting the flaw. pisapapeles.net · wwwhatsnew.com · www.datasecuritybreach.fr
- [○ 1 SOURCE] Alfredo Pesoli, CEO of Bynario, identified the flaw using automated detection systems. pisapapeles.net
- [○ 1 SOURCE] The vulnerability was assigned a severity score of 9.8 out of 10. pisapapeles.net
- [● 4 SOURCES] The flaw allows remote attackers to access a Mac without a password or user interaction via the Screen Sharing service. pisapapeles.net · wwwhatsnew.com · cybernoz.com · www.datasecuritybreach.fr
- [● 4 SOURCES] The vulnerability is officially registered as CVE-2026-65400. pisapapeles.net · wwwhatsnew.com · cybernoz.com · www.datasecuritybreach.fr
- [● 2 SOURCES] Apple released an emergency update to fix vulnerability CVE-2026-65400. pisapapeles.net · wwwhatsnew.com
- [● 3 SOURCES] The vulnerability affects macOS Sequoia, Sonoma, and Tahoe versions. pisapapeles.net · wwwhatsnew.com · www.datasecuritybreach.fr