Reported Mac Screen Sharing Flaw Targets Exposed Systems
Reports say attackers are exploiting an alleged Screen Sharing authentication bypass on internet-exposed Macs, though key claims remain unconfirmed by Apple.
What you need to know
- Tom’s Hardware reported active exploitation of alleged Screen Sharing flaw CVE-2026-65400 on 16 August.
- The reported attacks target Macs exposed to the internet through TCP port 5900.
- Apple’s publicly indexed security pages do not currently confirm the reported CVE or the claimed follow-up patches.
Report says internet-exposed Macs are under attack
Mac owners who use Screen Sharing for remote access should check how their systems are exposed after a report of active attacks against an alleged critical macOS flaw.

Tom’s Hardware reported on Sunday 16 August that attackers had exploited CVE-2026-65400 against Macs with Screen Sharing enabled and TCP port 5900 reachable from the public internet. The publication said the Dutch National Cyber Security Centre had reported the activity, with attackers allegedly gaining root access and installing Monero cryptocurrency-mining software.
However, the central claims have not yet been independently confirmed in the official Apple, CISA, NCSC-NL and NVD material retrieved for this report. That matters: the account is detailed and plausible, but Apple’s publicly indexed security documentation does not currently list CVE-2026-65400 or confirm the reported emergency updates said to address it.
The immediate practical concern is therefore narrow but serious. It is not a warning that every Mac is remotely vulnerable by default. The reported attacks concern systems deliberately configured for Screen Sharing and exposed directly to the internet, specifically via port 5900.
What the reported flaw is said to do
According to Tom’s Hardware, CVE-2026-65400 is an authentication bypass in macOS Screen Sharing. The publication attributed the following impact statement to an Apple advisory:
“authenticate to Screen Sharing without valid credentials”
Tom’s Hardware said that this could allow an attacker to reach a vulnerable Screen Sharing service without a valid login, then obtain root-level access to the Mac. It further reported that compromised machines had been used to run Monero-mining software.
Those are the most alarming parts of the story, and also the parts that have not been independently verified through the official records accessible in the research. There is no confirmed public detail on the precise bypass mechanism, the number of affected Macs, who is behind the activity, the mining software involved or whether every Mac on the named macOS versions is affected.
The report also said CISA raised the flaw’s CVSS severity score from 7.1 to 9.8, the critical band, on 14 August. Tom’s Hardware described that change as reflecting an attack requiring no privileges, with full potential impact on confidentiality, integrity and availability, and exploitation that could be automated. The accessible NVD record did not independently expose those details.
Apple’s available pages do not yet match the report
The update picture is currently inconsistent. Tom’s Hardware said Apple issued out-of-band updates on 6 August for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Tom’s Guide separately reported those same later version numbers during the week of its own article.
Yet Apple’s security-release page retrieved for this story lists macOS Tahoe 26.6, macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8, all released on 27 July. It does not list the reported 6 August releases. The retrieved Apple material also does not identify CVE-2026-65400 as fixed in a security update.
Apple’s security-content page for macOS Tahoe 26.6 does document several separate Screen Sharing Server vulnerabilities. They include CVE-2026-43779, involving the possible interception of network connections intended for another process; CVE-2026-43777, which could permit a remote denial of service; and CVE-2026-43760, which could allow an app to access user-sensitive data.
Tom’s Hardware characterised CVE-2026-43760 as an earlier Screen Sharing issue that required valid credentials, contrasting it with the alleged no-credentials scenario for CVE-2026-65400. Apple’s page confirms that CVE-2026-43760 affected Screen Sharing Server, but describes a different impact from the reported root-access and cryptomining campaign.
What UK Mac owners should do now
For most people, this is unlikely to be an urgent panic-inducing Mac emergency. A laptop or desktop used normally at home, with Screen Sharing switched off and no port forwarding configured on the router, does not match the conditions described in the report.
Owners who use Screen Sharing to reach a Mac from outside their home, workplace or studio should take the report more seriously. Check whether Screen Sharing is enabled, whether the Mac can be reached from the public internet, and whether port 5900 has been forwarded through a router or firewall. Disabling Screen Sharing when it is not needed, or removing public exposure to port 5900, reduces the reported attack surface.
It is also sensible to check for available macOS updates through the normal update settings. But owners should not assume that a particular version is confirmed to fix CVE-2026-65400: the Apple documentation retrieved for this story does not substantiate the specific versions reported by Tom’s Hardware and Tom’s Guide.
What happens next
The key outstanding question is whether Apple, CISA, NCSC-NL or NVD publishes a directly accessible advisory confirming the CVE, affected versions and remediation. Until then, the strongest claims around critical severity, active exploitation, root access and Monero mining remain reported rather than independently established facts.
That uncertainty should not obscure the useful lesson for ordinary buyers and smaller organisations. Remote-management features are valuable, but exposing them directly to the internet creates risk when security assumptions fail. For any Mac configured for remote administration, reducing unnecessary public access is the most immediate response while the reported vulnerability and its patch status are clarified.
Why it matters
Most UK Mac owners are unlikely to have Screen Sharing exposed directly to the internet, but remote-access setups at homes and small businesses deserve immediate scrutiny. The uncertainty around the reported fix makes sensible configuration changes especially important: disabling unneeded Screen Sharing and closing public access to port 5900 reduce the reported attack surface while Apple’s documentation remains unclear.
