CVE Tools
Back to feed
Exploited in the wild macOS mobile Screen Sharing Apple auth-bypass

Vulnerability giving attackers full control of Macs is under active exploitation

Ars Technica (Security)·By Dan Goodin··1 min read
CVE Tools coverage

Dutch cyber officials have confirmed active exploitation of a high-severity vulnerability in macOS that grants attackers full system control. Known as CVE-2026-65400, the flaw exists within the operating system's screen sharing feature and allows unauthorized remote execution of malicious code. Attackers have successfully obtained root access to compromised machines, often deploying Monero cryptocurrency miners. Apple has released patches for macOS Tahoe, Sequoia, and Sonoma to address this issue.