In the course of my own analysis of cyber threats, I identified an alarming attack vector targeting Mac owners. It involves the exploitation of a vulnerability in the Screen Sharing component, through which attackers gained full control over devices, stole confidential data, and deployed hidden Monero miners. The scale of the incident and the number of victims remain classified, which in itself raises questions about the depth of the intrusion.
The issue was officially documented on August 12, when the Netherlands National Cyber Security Centre (NCSC) published a report. The initial risk assessment on the CVE-2026-65400 scale, assigned by the U.S. Cybersecurity and Infrastructure Security Agency, was 7.1 out of 10. However, within just two days, this figure was radically revised to a critical 9.8 points. Such a rapid escalation in the rating underscores just how serious the security breach turned out to be.
Technical details and Apple's response
The root of the problem lies in the ability to gain unauthorized access to a Mac via Screen Sharing without any authentication. This makes the vulnerability an ideal tool for remote attacks, especially given that the "screen sharing" feature, although disabled by default, is often activated by users for convenient remote administration of servers and workstations.
Apple has already released patches closing this hole in the macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 updates. Nevertheless, as Censys scan data shows, tens of thousands of hosts on the network remain potentially vulnerable. Researcher Ryan Doud from Huntress strongly recommends that all macOS users immediately install the updates to avoid becoming the next victim.
This situation is yet another reminder that even the Apple ecosystem, traditionally considered closed and secure, is not immune to sophisticated attacks. Earlier this year, the AI model Claude Mythos was already helping "white hat" hackers bypass macOS protective mechanisms, including Memory Integrity Enforcement, which points to the growing complexity of cyber threats.
My comment: This incident highlights an alarming trend: mining botnets are becoming increasingly sophisticated, targeting high-performance devices such as Macs. The rise in the CVE rating from 7.1 to 9.8 in two days is a rare occurrence, signaling that the initial assessment was catastrophically underestimated. Users should not only update their software but also reconsider the need to use Screen Sharing on public networks.