{"id":813778,"date":"2026-08-14T21:38:08","date_gmt":"2026-08-14T21:38:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/813778\/"},"modified":"2026-08-14T21:38:08","modified_gmt":"2026-08-14T21:38:08","slug":"vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/813778\/","title":{"rendered":"Vulnerability giving attackers full control of Macs is under active exploitation"},"content":{"rendered":"<p>Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.<\/p>\n<p>\u201cThe NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,\u201d the Netherlands National Cyber Security Centrum <a href=\"https:\/\/advisories.ncsc.nl\/2026\/ncsc-2026-0280.html\" rel=\"nofollow noopener\" target=\"_blank\">warned<\/a> earlier this week. \u201cIn all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.\u201d<\/p>\n<p>Do you know if your screen sharing is on?<\/p>\n<p>The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS <a href=\"https:\/\/support.apple.com\/en-us\/148170\" rel=\"nofollow noopener\" target=\"_blank\">Tahoe<\/a>, <a href=\"https:\/\/support.apple.com\/en-us\/148171\" rel=\"nofollow noopener\" target=\"_blank\">Sequoia<\/a>, and <a href=\"https:\/\/support.apple.com\/en-us\/148172\" rel=\"nofollow noopener\" target=\"_blank\">Sonoma<\/a>. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the \u201cstate management,\u201d which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.<\/p>\n<p>A video of the exploit in action can be found <a href=\"https:\/\/xcancel.com\/calif_io\/status\/2086022794840793454\" rel=\"nofollow noopener\" target=\"_blank\">here<\/a>. Details of CVE-2026-65400 <a href=\"https:\/\/blog.calif.io\/p\/no-country-for-old-passwords\" rel=\"nofollow noopener\" target=\"_blank\">became public<\/a> at last week\u2019s Black Hat security conference. Apple said last week that CVE-2026-65400 \u201cmay\u201d allow an attacker without credentials to gain access to a Mac. It\u2019s unclear why Apple hedged, but softening language is common among most tech developers when disclosing vulnerabilities.<\/p>\n","protected":false},"excerpt":{"rendered":"Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under&hellip;\n","protected":false},"author":2,"featured_media":813779,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[74],"class_list":["post-813778","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/813778","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=813778"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/813778\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/813779"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=813778"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=813778"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=813778"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}