Exploited in the wild macOS mobile Screen Sharing Apple auth-bypass
Vulnerability giving attackers full control of Macs is under active exploitation
CVE Tools coverage
Dutch cyber officials have confirmed active exploitation of a high-severity vulnerability in macOS that grants attackers full system control. Known as CVE-2026-65400, the flaw exists within the operating system's screen sharing feature and allows unauthorized remote execution of malicious code. Attackers have successfully obtained root access to compromised machines, often deploying Monero cryptocurrency miners. Apple has released patches for macOS Tahoe, Sequoia, and Sonoma to address this issue.