A few weeks ago, Apple released several macOS security updates to address a serious vulnerability within its screen sharing tool. At the time, the insect had not yet been spotted in the wild. It was more about “better safe than sorry”. Today, we see that it is wreaking havoc in the Netherlands, according to a report from Ars Technica.
This vulnerability allows an attacker to view a user’s screen, open files, and do just about anything they want on the victim’s computer. It’s as if they physically own the machine.
Dutch officials at the Netherlands National Cyber Security Center issued a warning and said they had received notifications that the vulnerability was being used on “multiple systems.” In all cases, the attackers received root access and downloaded crypto mining software.
PoC for critical vulnerability in Apple macOS Screen Sharing (CVE-2026-65400).
If screen sharing is enabled, any network attacker can exploit the bug to log in under any account, without knowing the password.
We reverse engineered Apple’s unusual macOS 26.6.1 patch to understand… pic.twitter.com/WRIIwKx6yI
– California (@calif_io) August 8, 2026
As mentioned earlier, Apple has already released software patches. A software update was recommended back when this vulnerability was more or less theoretical. It is now an absolute necessity. The bug affects Tahoe, Sequoia, and Sonoma, and there are new versions of all three.
There are other things you can do to prevent this type of attack. It’s possible to completely block Apple’s Screen Sharing tool, which is an option in the System Settings menu. This will do the trick. Additionally, the vulnerability is exploited when port 5900 is exposed to the Internet. Security experts recommend keeping this port closed, especially when screen sharing.
This isn’t even the only big screen sharing bug to circulate over the past couple of weeks. Zoom experienced something similar and also released a patch. Stay safe out there.
