The Dutch National Cyber Security Centre (NCSC) detected a new vector of online attacks on Mac devices via a vulnerability in Screen Sharing.
The NCSC reported that attackers gained full control of the computer, stole data, and installed a Monero miner. The number of victims and suspected participants in the attacks was not disclosed.
The organization released a report on the vulnerability on August 12. At that time, the U.S. Cybersecurity and Infrastructure Security Agency assigned the threat CVE-2026-65400 a risk rating of 7.1 out of 10, but raised it to 9.8 two days later.

Apple has already fixed the bug in an update for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company's description, due to this bug, an attacker could gain access to a Mac via Screen Sharing without authorization.
The "Screen Sharing" function is disabled by default, but it is often enabled for remote access to Apple devices, including via remote servers.
Huntress researcher Ryan Daud urged macOS users to install the latest updates immediately. According to him, a search via Censys revealed tens of thousands of potentially vulnerable hosts.
Recall that in May, the AI model Claude Mythos helped "white-hat" hackers hack macOS. Researchers were able to bypass Apple's Memory Integrity Enforcement protection mechanism.
end-content




