If you have Screen Sharing turned on and haven’t updated your Mac recently, this is worth stopping to do right now, not later today. A vulnerability in Apple’s Screen Sharing tool, tracked as CVE-2026-65400, lets an attacker log into any account on an affected Mac without knowing the password, and it’s no longer just a theoretical risk. It’s actively being used against real machines.
Most security coverage of this bug is written for IT administrators. The actual situation, and what a regular Mac owner should do about it, is simpler than that coverage makes it look.
What This Bug Actually Lets an Attacker Do
The flaw sits in Apple’s Screen Sharing tool and affects macOS Tahoe, Sequoia, and Sonoma. An attacker who reaches an exposed Mac through it can view the screen, access files, and execute commands with the same control someone would have sitting physically at the machine, without ever needing a password for any account on it.
That last part is the detail that separates this from an ordinary bug: this isn’t a weak password problem or a phishing problem. The authentication step itself is broken, so having a strong password on your Mac doesn’t protect you here the way it normally would.
Why a Strong Password Doesn’t Save You Here
Screen Sharing normally authenticates you through a protocol called Secure Remote Password (SRP), a standard method for proving you know a password without ever sending the actual password over the network. The flaw in CVE-2026-65400 is in how that verification step gets handled, not in the passwords themselves. An attacker exploiting this bug isn’t guessing your password or intercepting it; they’re bypassing the check that’s supposed to require one at all.
That’s why this is classified as a pre-authentication vulnerability, the kind of flaw that’s especially dangerous because it doesn’t require tricking a user into anything or catching them with weak security habits. A Mac with a long, unique, well-managed password and this bug unpatched is exactly as exposed as one with a weak password, because the exploit never reaches the point where the password would normally matter.
This Isn’t a Hypothetical Risk Anymore
The Netherlands’ National Cyber Security Centrum reported finding this vulnerability actively exploited on multiple systems in the country. In every documented case, the attacker obtained root access, the highest level of system control on a Mac, and installed cryptocurrency mining software that runs silently in the background using your Mac’s processing power and electricity.
CISA raised this bug’s CVSS severity score to 9.8 out of 10 on August 14, up from an initial 7.1, specifically because the bug is straightforward to automate at scale once a working exploit exists publicly, which one now does. A score that high, on a bug already confirmed exploited in real attacks, is not a “patch when convenient” situation.
What a Cryptocurrency Mining Infection Costs You
It’s worth being specific about what the confirmed attacks did once they got in, since “installed cryptocurrency mining software” can sound abstract compared to something like stolen files. In practice, a cryptomining infection means someone else’s software runs continuously on your Mac, using your processor at high, sustained load to generate Monero, the specific cryptocurrency confirmed in these attacks, for the attacker’s benefit, not yours.
The real-world cost lands in a few concrete places: your electricity bill rises from sustained high CPU usage that has nothing to do with anything you’re doing, your Mac runs hotter and its fans work harder more of the time, and the constant load measurably shortens component lifespan compared to normal use. None of that requires the attacker to touch your personal files or accounts at all; root access plus a mining payload is a complete, self-contained monetization strategy for whoever’s running the attack, which is part of why this specific exploit was attractive enough to use at scale once a public proof-of-concept existed.
Apple Already Fixed It. The Fix Only Works If You Install It.
Apple shipped patches for all three affected macOS versions: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. These were released as a precaution before active exploitation was confirmed, which means anyone who updated promptly when the patch first came out was already protected before this became an active, in-the-wild threat. If you haven’t updated since early August, you’re running a version with a publicly known, actively exploited hole in it.
Check your version and update through System Settings > General > Software Update. If a newer version than the ones listed above is available by the time you’re reading this, install that instead; Apple’s patches are cumulative, so a later update still includes this fix.
If You Can’t Update Right Away, Do This Instead
Updating is the real fix, but if you’re not in a position to do it immediately, two things meaningfully reduce your exposure in the meantime:
- Turn off Screen Sharing entirely. System Settings > General > Sharing, and toggle Screen Sharing off. If you don’t actively use it to remote into your Mac from another device, there’s no reason to leave it running regardless of this specific bug.
- Make sure port 5900 isn’t exposed to the internet. That’s the port Screen Sharing uses, and the real-world attacks reported so far specifically targeted Macs with this port reachable from outside the local network, typically through a router misconfiguration or manual port-forwarding setup. If you never intentionally set up remote access to your Mac from outside your home network, this port should not be open at all.
Neither of these is a substitute for actually installing the patch. They reduce risk while you wait; they don’t close the hole the way the update does.
“I Don’t Use Screen Sharing” Isn’t Automatically Safe
It’s worth checking rather than assuming, because Screen Sharing can end up enabled without a deliberate, recent decision to turn it on. It’s possible to have switched it on once, years ago, for a single remote-support session or to help a family member with their Mac, and simply never switched it back off. It’s also possible for it to have been enabled during initial Mac setup or migration from an older machine, carried forward without anyone specifically choosing it in the current moment.
The check costs nothing: open System Settings > General > Sharing and look at whether Screen Sharing shows as on or off. If you genuinely don’t remember ever using it, that’s the easiest case to resolve, since there’s no workflow to preserve by turning it off.
Worth Knowing: This Wasn’t a One-Off
Apple wasn’t alone in dealing with a screen-sharing authentication flaw around the same period; Zoom had a comparable vulnerability in its own screen-sharing feature and shipped a patch for it too. That’s less a coincidence than a reminder that screen-sharing tools are a genuinely attractive target: when they work correctly, they’re designed to hand over exactly the kind of control this bug hands over for free, which is precisely why a flaw in the authentication layer is so severe wherever it turns up.
If you use screen-sharing or remote-access tools of any kind, whether built into your OS or a separate app, treating their update notifications as urgent rather than routine is a reasonable habit to take away from this specific incident, not just a one-time fix for this one bug.
*Sources: Engadget — “That Apple Screen Sharing bug has now been seen in the wild, so please update macOS”; CVSS score and exact patch version numbers cross-checked against Tom’s Hardware’s coverage of CVE-2026-65400.*



