← Back to Daily Briefing (#LPE)

CVE-2026-65400 is a high-severity state management vulnerability within the macOS screen sharing capability affecting macOS Tahoe, Sequoia, and Sonoma. Attackers targeting exposed Port 5900 can bypass authentication to gain immediate root-level access, enabling full remote takeover of the user interface, including screen visibility and input manipulation. The Netherlands National Cyber Security Centrum (NCSC) has confirmed active exploitation in the wild, primarily utilizing the flaw to deploy Monero cryptominers for resource theft. Immediate remediation requires updating to the latest macOS versions and implementing network restrictions to prevent direct internet exposure of VNC services.

  • Vulnerability Overview: State Management Flaw

    • Identified as CVE-2026-65400 with a CVSS severity rating of 7.1/10.
    • Targets a critical logic error in the "state management" of the macOS screen sharing feature.
    • Impacts three major OS iterations: macOS Tahoe, Sequoia, and Sonoma.
  • Attack Vector and Mechanics

    • Exploitation occurs when Port 5900 (Screen Sharing/VNC) is exposed directly to the internet.
    • The flaw allows threat actors to completely bypass authentication requirements.
    • Successful exploitation results in the attacker gaining root-level privileges on the target system.
  • Operational Impact and Exploitation Status

    • Grants full remote control over the target machine, including the ability to view the screen and manipulate the keyboard and mouse.
    • Confirmed active exploitation by threat actors as reported by the NCSC.
    • Current observed payloads center on cryptojacking, specifically the installation of Monero crypto miners.
  • Remediation and Defensive Strategy

    • Deploy immediate security patches for macOS Tahoe, Sequoia, and Sonoma.
    • Disable the "Screen Sharing" capability on all systems where it is not strictly required.
    • Eliminate direct internet exposure of Port 5900; transition to secure SSH tunneling or VPN-based access.

Related posts

  1. it.slashdot.org — Vulnerability Giving Attackers Full Control of Macs Is Under Active Exploitation
  2. Itservicealerts
  3. Ground
  4. Healsecurity
  5. Machash
  6. Reddit
  7. News
  8. Lemmy

LINK COPIED TO CLIPBOARD