Update Your Mac ASAP to Avoid This Screen Sharing Bug
Apple has released an emergency macOS update that patches a critical flaw in its built-in Screen Sharing tool. The vulnerability (CVE-2026-65400) lets a remote attacker bypass authentication, log in without a password, and gain full control of a Mac, including root access. Government security agencies have already caught attackers abusing the bug to install hidden Monero cryptocurrency miners on affected systems.
The issue comes from poor state management during authentication in Screen Sharing, which uses virtual network computing (VNC) on TCP Port 5900—the default port for remote desktop connections—to let one computer view another. If this port is accessible online, an attacker can take control of the system, including viewing the screen, using the keyboard and mouse, accessing files, running code, and remaining on the system without permission. Before the patch, one researcher found 40,000 Macs vulnerable to this exploit.
The US Cybersecurity and Infrastructure Security Agency (CISA) increased the vulnerability’s CVSS severity score to a worrisome 9.8 out of 10 (Critical) after finding that the attack can be automated and allows full compromise.
Apple released a patch on August 6 that updates macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. If you can’t update right away, it’s recommended that you at least turn off Screen Sharing in System Settings > General > Sharing to block TCP port 5900 from the internet via your router or firewall.