Dutch officials have sounded the alarm over a high-severity macOS flaw that allows attackers to execute malicious code, with reports of active abuse on systems where port 5900 was accessible from the internet. In all these cases, root access was gained and Monero crypto miners installed. The vulnerability, tracked as CVE-2026-65400, affects macOS Tahoe, Sequoia, and Sonoma, with a severity rating of 7.1 out of 10 and stems from a bug in the macOS screen sharing capability. A flaw in 'state management' is to blame for this vulnerability. Apple has issued a patch but hedged on the severity, perhaps wary of alarming users.
The Dutch National Cyber Security Centrum highlighted that if your screen sharing was active and accessible from the internet, you should check immediately. A video demonstrating the exploit can be viewed online, but it's best to assume the worst until proven otherwise. This incident serves as a stark reminder of the ever-evolving landscape of digital security threats.
The crypto mining aspect is particularly concerning, as it not only exploits users' systems for financial gain but also drains resources, potentially leading to system crashes or slow performance. With such vulnerabilities in the wild, it's crucial for users to stay vigilant and regularly update their software to mitigate risks.
For those who use macOS, now might be a good time to review your security settings and ensure that all updates are installed. Apple has provided a patch, but it’s important to keep an eye out for any new advisories or patches in the future. As always, keeping your systems secure is paramount.







