Apple has patched a newly disclosed macOS vulnerability across three versions of its desktop operating system after security researchers warned that attackers were actively exploiting it to gain root access and deploy cryptocurrency mining malware.
The flaw, identified as CVE-2026-65400, carries a CVSS score of 9.8 out of 10, according to an advisory from the Netherlands’ National Cyber Security Centre. The agency says the issue stems from improper state handling during authentication. If macOS Screen Sharing is enabled, an attacker on the network can exploit the flaw to log in without valid credentials. Normally, the operating system would block such an attempt.
The flaw affects macOS Sequoia, Sonoma, and Tahoe. Apple has released patched versions in the following updates:
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
- macOS Tahoe 26.6.1
Apple published a separate security bulletin for each release and credited Alfredo Pesoli with discovering the vulnerability. Pesoli is the co-founder and CEO of Bynario, a cybersecurity company that uses automation and AI to help find security vulnerabilities.
The NCSC-NL says the vulnerability was discovered earlier this month. About a week before issuing its alert, the agency found evidence that a working proof-of-concept had already been shared publicly online.
Unknown attackers have reportedly used the proof-of-concept to target multiple Mac systems through port 5900, which is used by macOS Screen Sharing. The attackers were able to gain root access on vulnerable machines and install a Monero cryptomining trojan.
Root-level access poses a serious risk because it can bypass built-in security protections and let attackers add other malicious software to the system. The attackers in this case installed a cryptocurrency miner, although the same access could have been used for more harmful activities.
Mac users should install the patched versions as soon as they are available. It is also worth disabling Screen Sharing when it is not in use and keeping port 5900 from being directly accessible over the internet.
Maybe you would like other interesting articles?

