Tech & AI

Update variation your Mac: Screen Share vulnerability gives attackers full control of your computer

Mac users, if you haven't updated your MacBook or desktop Mac computer in the last week or so, install that latest update variation now.The most recent Mac related update term from Apple includes a patch for a major vulnerability that could allow an attacker to take over a targeted Mac.The exploit involves an authentication bug…

Mysterious hand using MacBook

Mac users, if you haven’t updated your MacBook or desktop Mac computer in the last week or so, install that latest update variation now.

The most recent Mac related update term from Apple includes a patch for a major vulnerability that could allow an attacker to take over a targeted Mac.

The exploit involves an authentication bug in Mac’s Screen Share functionality, Ars Technica reported. An unauthorized party can exploit the bug to take control of a user’s keyboard and mouse when screen sharing is enabled.

The vulnerability is being tracked as CVE-2026-65400. Apple’s own explanation of the security update variation warns users that this security issue could allow an attacker on the network variation to access a Mac without valid credentials.

The Netherlands National Cyber Security Centre (NCSC) warned about the vulnerability last week after the exploit was initially made public.

Cybersecurity firm alternative Calif recently shared how they reverse-engineered Apple’s recent macOS patch as it “piqued our curiosity.” As Calif explained in a blog post, “Apple does not ship an update variation out of band unless something is critical.”

From there, Calif researchers uncovered the Screen Share vulnerability. The firm variation posted a video demonstrating the attack.

According to the NCSC report alternative on the vulnerability, the exploit results from “insufficient related state term related management term during the authentication process.” If Screen Share is activated on a Mac, the macOS firewall exposes port 5900 to third parties over the internet. In turn, unauthorized access can occur via authentication attempts that wouldn’t usually be accepted.

The NCSC reports that it has received notice that the exploit has been observed in the wild. The vulnerability has reportedly been used to obtain root access on an affected system. In this case, a Monero crypto miner was installed by the unauthorized user.

The first researcher to discover the exploit found roughly 40,000 Macs with Screen Share enabled and reachable from the internet, which gives a sense of just how many potential targets were out there at any given time.

Apple released the patch last week for macOS Tahoe, Sequoia, and Sonoma. Mac users are urged to install the latest security related update term.

Source: https://mashable.com/tech/apple-mac-macbook-screen-share-vulnerability