Apple Screen Sharing Bug Is Being Exploited Right Now. Update Your Mac

Here’s the thing about Macs — most people think they’re invincible. No viruses, no hackers, nothing bad ever happens.

That’s not true. And this week is a good reminder.

Apple pushed out an emergency update on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. It fixed one thing: a Screen Sharing vulnerability tracked as CVE-2026-65400.

Here’s what that bug actually does. If you have Screen Sharing enabled on your Mac, your computer opens port 5900 to the network. That’s how the feature works — it lets someone else view and control your screen remotely.

The problem? Apple messed up the authentication check. An attacker on the same network could connect to your Mac without any password at all. No credentials needed. Just a connection.

And they could do more than just look.

The Dutch National Cyber Security Centre (NCSC-NL) confirmed on August 12 that attackers are actively exploiting this. In every case they’ve seen, the attacker got root access — that’s the highest level of control on a Mac — and installed a Monero cryptocurrency miner. Your Mac becomes their mining rig. They use your CPU, your electricity, your internet. You just get a slower computer and a bigger power bill.

Wait, I should have said this earlier — Screen Sharing is off by default on a fresh Mac. So if you’ve never turned it on, you’re probably fine. But if you’ve ever used it for remote work, tech support, or just messing around, it might still be on. One researcher found roughly 40,000 Macs with Screen Sharing enabled and reachable from the internet. That’s a lot of targets.

The scary part? The vulnerability itself isn’t complicated. Researchers built a working proof of concept in hours with AI help. And the severity score got bumped from 7.1 to 9.8 out of 10 — critical. Because it requires no user interaction, no password, nothing. Just an open port.

So what do you actually do about it?

Go to System Settings > General > Software Update. Check if you’re on Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 — or newer. If not, install the update now. It takes maybe five minutes.

If you don’t need Screen Sharing at all, turn it off. System Settings > General > Sharing, flip the toggle. Done.

That’s really it. Update, or turn it off. There’s no middle ground here — the bug doesn’t ask for permission, and it doesn’t need a password.

Honestly? I’m not sure how many people this is actually going to hit. Most casual users never enable Screen Sharing. But if you’re a developer, or you manage remote Macs, or you’ve ever let a friend help you fix something — check.

I’ll be honest — I turned Screen Sharing on once, years ago, to let a colleague help me debug something. I forgot about it completely. It was probably on for months. That’s the thing about these features. You enable them for one specific task, and they just sit there, quietly waiting.

Not anymore for me. I checked. It was off.

One more thing — this isn’t the only Screen Sharing bug Apple fixed recently. There’s another one, CVE-2026-43760, but that one requires the attacker to already have a VNC password. This one? No password needed. That’s why it’s critical.

I’m not saying this to scare you. I’m saying it because I use a Mac every day, and I assume most of you do too. Updates are annoying. They interrupt your workflow. But this one takes five minutes.

Just do it.

I’ll keep an eye on this and report back if anything changes.