CVE Tools

Vulnerability giving attackers full control of Macs is under active exploitation

Ars Technica (Security)By Dan Goodin

Reported exploitedmacOSScreen Sharing

Our summary

Dutch cyber officials have confirmed active exploitation of a high-severity vulnerability in macOS that grants attackers full system control. Known as CVE-2026-65400, the flaw exists within the operating system's screen sharing feature and allows unauthorized remote execution of malicious code. Attackers have successfully obtained root access to compromised machines, often deploying Monero cryptocurrency miners. Apple has released patches for macOS Tahoe, Sequoia, and Sonoma to address this issue.

Read at Ars Technica (Security)

Ars Technica (Security) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store