The Dutch National Cyber Security Centre (NCSC) has reported a new online attack vector targeting Mac devices via a vulnerability in Screen Sharing.
According to the NCSC, attackers were able to gain complete control over the affected computers, steal data, and install Monero miners. The exact number of victims and those involved in the attacks remains undisclosed.
The organization released a report on the vulnerability on August 12. Initially, the U.S. Cybersecurity and Infrastructure Security Agency assigned a risk rating of 7.1 out of 10 to the threat CVE-2026-65400, but two days later, it raised this rating to 9.8.
Source: U.S. Cybersecurity and Infrastructure Security Agency.Apple has already patched the flaw in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company, the bug allowed attackers to access Macs through Screen Sharing without authorization.
The Screen Sharing feature is typically disabled by default, but it is often enabled for remote access to Apple devices, including via remote servers.
Huntress researcher Ryan Dowd urged macOS users to promptly install the latest updates. He noted that searches through Censys have identified tens of thousands of potentially vulnerable hosts.
It is worth mentioning that in May, an AI model named Claude Mythos assisted "white" hackers in breaching macOS. Researchers were able to bypass Apple’s Memory Integrity Enforcement protection mechanism.
