All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
The Screen Sharing tool on macOS is no longer a harmless way to remotely control your Mac and access its screen as if you were sitting right in front of it. Researchers have found a new vulnerability in the tool that lets an attacker control your screen, keyboard, and mouse.[1]
Once the attacker gains control of your system, they could use it to interact with anything visible on the screen, steal saved passwords, sensitive personal data, browser sessions, and logged-in account details, install further spyware or ransomware, or establish a persistent backdoor on your system.
Luckily, Apple already released a fix to this a few weeks back[2] — although at the time, these macOS security updates were optional. But with new instances of the flaw being exploited by hackers, updating is now non-negotiable.
Here’s everything you need to know about this Mac vulnerability, why it’s a security gap you need to immediately close, and the steps you can take to protect yourself.
What can you do to protect yourself
Bottom line
How this macOS Screen Sharing flaw can be exploited
When the vulnerability was first discovered, security researchers didn’t find any instances of attackers exploiting it.
However, a new advisory from the NeNational Cyber Security Centrum (NCSC), Netherlands, has revealed that the bug is now being actively exploited in the wild.
When Screen Sharing is enabled, the macOS firewall opens port 5900, making it accessible over the internet. Port 5900 is the default Transmission Control Protocol (TCP) port used by Virtual Network Computing (VNC), which is a protocol for remote desktop access.
Essentially, this lets one computer view and control another’s screen, keyboard, and mouse remotely.
By default, most home routers and firewalls block inbound connections to port 5900 from the public internet. But if it’s exposed — as is possible with this vulnerability — it could be abused by anyone on the internet.
Tracked as CVE-2026-65400, attackers are using this bug to install Monero miners — a cryptocurrency miner — on victims’ systems. These miners secretly hijack the victim’s computing resources to generate cryptocurrency for the attacker, causing significant system slowdowns and increased power consumption.
While researchers haven’t observed other forms of system compromise, an internet-facing port 5900 could allow an attacker to gain complete control of your system. This could open up a world of possibility:
- Just as easily as attackers are installing the miner, they could install spyware, ransomware, or other malware on your computer that could continuously exfiltrate sensitive personally identifiable information.
- Because the attacker can view a victim’s screen, they could also directly intercept any sensitive documents, emails, or messages visible on the screen, including two-factor authentication (2FA) codes. They could then steal browser sessions and credentials for any logged-in accounts, such as your banking or social media accounts.
- Attackers could even open applications, browse your file system, and harvest data from your Mac PC.
- The NCSC advisory also observed that attackers gained root access during these attacks, which means that they’re well capable of gaining full administrative control over the device’s operating system.
- Root access also means attackers could create hidden user accounts or add their own SSH keys, giving them a backdoor into the system even if the Monero miner is found and removed. A surface-level cleanup might not be enough to close this backdoor.
What can you do to protect yourself
Although the vulnerability is capable of causing significant damage, including allowing hackers to use your sensitive data to launch phishing attacks for identity theft or financial fraud, there are still some steps you can take to fix this security loophole.
- Install Apple’s update: Apple has already released patches for macOS Tahoe, Sequoia, and Sonoma. Since there was no known exploitation earlier, the update seemed more or less optional. But now, with cases of threat actors exploiting the vulnerability against victims, updating your macOS software has become a necessity.
- Use a virtual private network (VPN): A VPN can help keep port 5900 from being exposed directly to the public internet. Instead of forwarding port 5900 through your router and making it accessible to anyone online, you can keep it closed to the public internet and make Screen Sharing reachable only to devices that have authenticated into your private network through the VPN.
- Use Screen Sharing only when needed: Screen Sharing on macOS isn’t enabled out of the box. A user has to explicitly turn it on. So, users who have turned it on at some point and forgotten about it are more susceptible to this vulnerability. As a safe practice, toggle Screen Sharing only when you need it. Enable it before a session, complete the work, and then disable it again. You can also micromanage which users or administrators are allowed to connect through Screen Sharing, which further reduces the risk.
- Use a third-party antivirus program: If you suspect that you’ve already been impacted by this vulnerability, using an antivirus program can help you mitigate the threats. Antivirus tools come with signature-based and behavioral detection engines that can scan for known crypto miners like Monero miners. Additionally, they’re capable of detecting sudden spikes in resource usage or unexpected outbound network connections. However, it’s worth noting that antivirus is primarily a post-exploitation protection measure here and cannot be relied upon to prevent the initial exploitation of the Screen Sharing vulnerability.
Bottom line
The new macOS Screen Sharing bug could allow an attacker to access your screen, keyboard, and mouse and potentially steal everything on your system, including your passwords, login credentials, and personally identifiable information.
However, the good news is that Apple has already shipped patches for the vulnerability for macOS Tahoe, Sequoia, and Sonoma. So, there’s a simple way to close this security gap and protect yourself.
However, if you’re on an older macOS version, ensure that you enable Screen Sharing only when needed, and even then, avoid exposing port 5900 directly to the internet and use a VPN to route your connections instead. Additionally, you could use a third-party antivirus to detect and remove any existing infections.