Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Hackers Exploit Critical macOS Screen Sharing Flaw to Gain Root Access

Hackers Exploit Critical macOS Screen Sharing Flaw to Gain Root Access

Last updated:August 17, 2026
Human Written
  • A serious flaw in macOS lets hackers take full control of a Mac from far away.

  • Dutch officials say hackers are already using this bug to break into computers.

  • Apple released a fix, but many Macs still stay open to attack.

Hackers Exploit Critical macOS Screen Sharing Flaw to Gain Root Access

Hackers are now using a serious bug in macOS. This bug lets them break into a Mac without a password. Dutch cybersecurity officials shared this warning earlier in the week.

The Netherlands National Cyber Security Centrum, known as NCSC, gave the alert. The agency said hackers already broke into several Macs. Attackers gained root access, then planted crypto mining software on each machine.

Root access is the highest level of control on a computer. Once hackers reach that level, they can change almost anything on the machine. This makes the bug far more dangerous than a normal login problem.

Details of the Vulnerability

The bug carries the code CVE-2026-65400. Apple fixed it last week for macOS Tahoe, Sequoia, and Sonoma, according to TheHackerNews. The flaw sits inside macOS Screen Sharing, a built-in tool. For everyday users, screen sharing lets one computer view and control another over the internet.

The bug first carried a severity score of 7.1 out of 10. The United States cyber agency CISA later raised that score to 9.8. This change marked the bug as critical, per Tom’s Hardware. CISA also updated its notes. It now says the attack can run fully on its own, without human help.

A hidden fault inside the system’s “state management” caused the problem. State management tracks past actions, user clicks, and other computer activity. When this tracking breaks, attackers can slip in without a password.

The flaw lives inside a background process called screensharingd. This process handles a security check named Secure Remote Password. That check normally proves a user knows a password, without ever sending the password itself, per Tech Times. The broken check let attackers skip that proof completely.

The public first learned about this flaw at last week’s Black Hat security event, according to Slashdot. Apple admitted the flaw “may” let an outsider reach a Mac without login details. Tech companies often choose soft words like this when explaining security problems.

How Hackers are Exploiting the Flaw

NCSC shared new details about the ongoing attacks. Hackers targeted Macs that left port 5900 open to the internet, the agency noted. Officials confirmed root access was gained, and a Monero mining program was placed on every hacked machine they reviewed.

Port 5900 opens automatically once a person turns Screen Sharing on. Most home routers and office firewalls block that port by default. Only Macs with the port exposed, whether on purpose or by mistake, faced real danger. Some small businesses and remote workers expose this port without knowing it. That mistake can happen during setup of remote access tools.

Security experts suggest closing Screen Sharing ports for good, then using safer tools instead. A private network connection or a secure tunnel works better for remote access. Sadly, setting those tools up takes technical skill many users lack.

Attackers need no phishing email and no tricked click to break in. The flaw works directly over the internet, with no help from the Mac’s owner. That makes this attack far more dangerous than typical scams.

The aviation sector faces a similarly dangerous threat: a hacker has claimed to maintain root access to a major Asian airline’s booking system, allegedly holding more than 31 million bookings and 350,000 passenger records, with the ability to create fraudulent tickets across more than 40 airlines through private API connections.

For now, hackers only use this bug to install Monero miners. These programs quietly use a Mac’s processing power to earn digital cash for the attacker. Experts worry hackers could soon steal passwords or plant worse programs instead. A machine with root access offers nearly unlimited options to a skilled attacker.

How to Protect Your Mac

Update your Mac right away. Apple’s patch fixes the bug and blocks this attack completely. This single step removes the danger for most users. Turn off Screen Sharing whenever you are not using it. Open System Settings, then General, then Sharing. Flip the Screen Sharing switch off once your session ends.

Only turn Screen Sharing on for short, planned sessions. Turn it off the moment you finish. This habit shrinks the window hackers have to strike. Watch your Mac’s performance too. A slow or overheating Mac might mean a hidden miner runs in the background. Check your Activity Monitor for programs you do not recognize.

Stay alert for future updates from Apple and NCSC. New details about these attacks could still surface. Following trusted security news keeps you one step ahead of hackers. A quick software update today can save you a major headache later.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.