Severe attacks exploiting vulnerabilities related to screen sharing in macOS are occurring frequently.



It has become clear that a vulnerability related to authentication in macOS's

screen sharing function, 'CVE 2026-65400,' is being actively exploited in cyberattacks.

NCSC NL | Security Advisories
https://advisories.ncsc.nl/2026/ncsc-2026-0280.html



Vulnerability giving attackers full control of Macs is under active exploitation - Ars Technica
https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/

No Country for Old Passwords - Calif
https://blog.calif.io/p/no-country-for-old-passwords

According to the Netherlands Cybersecurity Centre (NCSC-NL), the vulnerability allows attackers to perform authentication attempts that would normally require valid credentials due to insufficient state management in the authentication process. Specifically, it allows attackers to log in to any account even without knowing the password.

X user Calif has released a video demonstrating how this vulnerability actually works. Calif was intrigued by Apple's emergency macOS update on August 6, 2026 , which is unusual as Apple doesn't usually release updates except for scheduled ones. He reverse-engineered the update and managed to execute the exploit in about four hours.



According to the NCSC-NL report, in all cases where this vulnerability was exploited, root access was granted to the system and a Monero cryptocurrency miner was installed. The Monero miner only secretly uses Mac resources to mine cryptocurrency, so the actual damage is not very significant. However, there is a risk that attackers could exploit the vulnerability to steal credentials or install malware capable of performing various other actions.

Apple has already released a patch, but if you want to use screen sharing safely, it's best to only turn it on when you need it.

in Security, Posted by logc_nt