Apple’s Screen Sharing Bug Is Being Exploited Right Now. Update Your Mac

Here’s the thing about Macs — most people think they’re invincible. No viruses, no hackers, nothing bad ever happens.

That’s not true. And this week is a good reminder.

Apple pushed out an emergency update on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. It fixed exactly one thing: a Screen Sharing vulnerability tracked as CVE-2026-65400.

What the bug actually does

If you have Screen Sharing enabled, your Mac opens port 5900 to the network. That’s how the feature is designed to work — it’s what lets someone else view and control your screen from another machine.

The problem is that Apple messed up the authentication check. An attacker on the same network could connect to your Mac without any password at all. No credentials. No prompt. Just a connection.

And they could do more than look.

The Dutch National Cyber Security Centre (NCSC-NL) confirmed on August 12 that attackers are actively exploiting this. In every case they’ve seen, the attacker got root access — the highest level of control on a Mac — and installed a Monero cryptocurrency miner. Your Mac becomes their mining rig. They use your CPU, your electricity, your internet. You get a slower computer and a bigger power bill.

Wait, I should have said this earlier. Screen Sharing is off by default on a fresh Mac. So if you’ve never turned it on, you’re probably fine. But if you’ve ever used it for remote work, tech support, or just messing around, it might still be on. One researcher found roughly 40,000 Macs with Screen Sharing enabled and reachable from the internet. That’s a lot of targets.

The scary part is how simple the bug is. Researchers built a working proof of concept in hours, with AI help. And the severity score got bumped from 7.1 to 9.8 out of 10 — critical — because it requires no user interaction, no password, nothing. Just an open port.

So what do you actually do about it?

Two things. One takes five minutes; the other takes ten seconds.

Update. Go to System Settings → General → Software Update. Check that you’re on Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 — or newer. If not, install it now.

Turn Screen Sharing off if you don’t need it. System Settings → General → Sharing, flip the toggle. Done. Honestly, do this one even after updating. A feature you switched on once for a single afternoon doesn’t need to be listening on a port for the next three years.

If you’re the type who parks Apple updates until the weekend, I get it. I ended up writing about why the 26.6.1 release was worth moving on for exactly that reason, and this is the same story on the Mac side.

That’s really it. There’s no clever middle ground here, because the bug doesn’t ask for permission and it doesn’t need a password.

If you’re wondering whether you already got hit: the signature of a mining infection would be a Mac that’s suddenly loud and warm while it’s sitting idle. Open Activity Monitor, sort by CPU, and see whether anything unfamiliar is pinned at the top with nothing to justify it. That’s not proof of anything, but it’s the cheapest check you can run, and it takes less time than reading this paragraph did.

One more thing worth knowing — exposure isn’t only about the open internet. The bug works from the same network, which means the coffee-shop Wi-Fi version of this matters as much as the internet-facing version. Turning Screen Sharing off closes both doors at once, which is why it’s the better habit to keep.

Honestly? I’m not sure how many people this is actually going to hit. Most casual users never enable Screen Sharing. But if you’re a developer, or you manage remote Macs, or you’ve ever let a friend log in to help you fix something — check.

I’ll be honest — I turned Screen Sharing on once, years ago, so a colleague could help me debug something. Then I forgot about it completely. It was probably on for months. That’s the thing about these features. You enable them for one specific task, and they just sit there, quietly waiting.

Not anymore for me. I checked. It was off.

One more thing, because I went looking: this isn’t the only Screen Sharing bug Apple fixed recently. There’s another one, CVE-2026-43760 — but that one requires the attacker to already have a VNC password. This one needs nothing. The gap between “needs a password” and “needs nothing” is the entire difference between a patch note and a headline.

I’m not saying this to scare you. I’m saying it because I use a Mac every day, and I assume most of you do too. Updates are annoying. They interrupt your workflow. But this one takes five minutes.

Just do it.

I’ll keep an eye on this and report back if anything changes.