Active Exploitation of macOS Screen Sharing Vulnerability Prompts Dutch Cybersecurity Warning
Threat actors are targeting exposed port 5900 to gain root access and deploy Monero miners on unpatched Apple systems.

Cybersecurity authorities in the Netherlands have issued a warning regarding an actively exploited security vulnerability in Apple Inc.'s macOS operating system that allows unauthorized remote users to take full control of affected computers without requiring login credentials, as first reported by Ars Technica.
The flaw, designated as CVE-2026-65400, impacts the built-in screen sharing functionality across several recent versions of Apple's desktop software, including macOS Tahoe, Sequoia, and Sonoma. Apple released software patches addressing the flaw last week after technical details were presented at the recent Black Hat security conference.
According to a public advisory released earlier this week by the Netherlands National Cyber Security Centrum (NCSC), attackers have been actively targeting vulnerable systems connected directly to the public internet. The Dutch agency noted that it received notifications confirming compromise across multiple machines where administrative root access was obtained.
In all observed instances of active exploitation, threat actors utilized their unauthorized access to install Monero cryptocurrency mining software, the NCSC stated. The mining programs silently siphon local computing resources to perform mathematical computations that generate digital currency for the attackers.
The vulnerability carries a severity rating of 7.1 out of 10. Security analysts trace the root cause to a defect in state management within the macOS screen sharing protocol—the subsystem responsible for tracking preceding system events, user interactions, variables, and environmental states.
Exploitation occurs specifically when network port 5900 is accessible to external internet traffic. When users enable screen sharing, the native macOS firewall automatically opens port 5900 to inbound connections. While standard hardware routers and enterprise firewalls typically block external traffic on this port by default, systems configured to override those settings remain exposed.
When disclosing the issue, Apple noted in its security advisory that the flaw "may" allow an unauthenticated attacker to obtain access to a Mac. Major technology vendors frequently utilize conservative phrasing in official vulnerability disclosures prior to full patch deployment across user bases.
Although current attacks appear limited to cryptocurrency hijacking, cybersecurity researchers warn that the vulnerability presents broader risks because attackers could potentially deploy more destructive software payloads, such as credential-stealing malware.
Security professionals strongly advise Mac users to apply Apple's latest security updates immediately. To mitigate risk further, experts recommend disabling screen sharing under System Settings > General > Sharing when not actively in use, or routing screen-sharing traffic through virtual private networks (VPNs) or SSH tunnels to keep port 5900 closed to the internet.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



