Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-15 ยท updated: 2026-08-15 ยท tags: [incident, active-exploitation, apple, macos, rce, crypto-mining, sector-global-macro] ยท confidence: high ยท affected_sectors: [global-macro] ยท au_impact: false

Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation

  • Source: Ars Technica
  • Date: 2026-08-15
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Entity: Apple macOS (Screen Sharing)

Summary

Ars Technica reports that CVE-2026-65400 โ€” a flaw in macOS Screen Sharing state management โ€” is under active exploitation. An unauthenticated remote attacker can log in to a Mac without a password, view the screen, and take control of the keyboard and mouse. The Netherlands NCSC warned of active attacks on systems with port 5900 exposed; observed intrusions obtained root and installed a Monero cryptocurrency miner. Apple shipped patches for macOS Tahoe, Sequoia and Sonoma within the last week.

Key Facts

  • CVSS 7.1 authentication bypass in macOS Screen Sharing
  • Affects systems with Screen Sharing exposed on port 5900
  • Exploitation observed in the wild; attackers achieved root and installed a crypto-miner
  • Apple patches now available for Tahoe, Sequoia and Sonoma

Sector

Global (Macro) โ€” Internet-exposed Screen Sharing services form a broad cross-sector attack surface.

Source

https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/

Reliability

Tier 2 โ€” Established cyber journalism; incident status confirmed.

Date

2026-08-15

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-15