HeadlinesBriefing favicon HeadlinesBriefing.com

Mac Vulnerability Under Active Exploitation

Ars Technica •
×

Dutch officials have issued a warning regarding a high-severity macOS vulnerability, CVE-2026-65400, which is currently under active exploitation. This flaw allows attackers to execute malicious code and gain full control of affected Macs.

The Netherlands National Cyber Security Centrum (NCSC) reported observing active abuse of this vulnerability on systems with port 5900 accessible from the internet. In such cases, attackers successfully gained root access and deployed Monero crypto miners.

Apple released a patch for macOS Tahoe, Sequoia, and Sonoma last week. The vulnerability, rated 7.1 out of 10, originates from a bug in the macOS screen sharing feature. A flaw in its "state management" enables remote parties to view the screen and control the keyboard and mouse without authentication. Details of CVE-2026-65400 were disclosed at the Black Hat security conference.