A patched macOS screen sharing bug is already being exploited by attackers to gain root access and mine cryptocurrency.
The Netherlands' National Cyber Security Centrum warned this week that CVE-2026-65400, a flaw in macOS's screen sharing feature, is under active attack on systems with port 5900 open to the internet. Screen sharing normally lets a remote party view a screen and control the keyboard and mouse; the bug lives in the "state management" code that tracks user interactions and system state. Apple rated the flaw 7.1 out of 10, high severity, not critical, and shipped a patch last week for macOS Tahoe, Sequoia, and Sonoma. The NCSC said every compromised system it examined ended up with root access and a Monero crypto miner installed.
Port 5900 is VNC's default port, and exposing it directly to the internet has been a bad idea for decades. This attack succeeds because someone left that door open, not because Apple's screen sharing is uniquely broken. Still, a state-management bug that escalates to root is a serious design failure, and the fact that abuse began before most users had patched shows attackers are watching Apple's release notes as closely as security researchers do.
If your Mac has screen sharing enabled and reachable from outside your network, the crypto miner is the least of your problems: patch first, ask questions later.