Apple has released an urgent security patch addressing a critical vulnerability in its Screen Share feature that could grant unauthorized users complete control over affected Mac computers. The flaw, tracked as CVE-2026-65400, stems from an authentication bug that allows attackers to manipulate keyboard and mouse functions on vulnerable systems. Mac owners are being strongly encouraged to download the latest update for macOS Tahoe, Sequoia, and Sonoma immediately.
The vulnerability arises from improper state management during the authentication process. When Screen Share is enabled, the macOS firewall opens port 5900 to external connections, potentially exposing machines to unauthorized access attempts that would normally be rejected. Security researchers discovered approximately 40,000 Macs with Screen Share active and accessible from the internet, indicating the broad scope of devices at risk. The Netherlands National Cyber Security Centre has confirmed that the exploit is already being actively used in real-world attacks.
Cybersecurity firm Calif uncovered the vulnerability while analyzing Apple’s emergency patch, noting that such out-of-band updates typically signal critical threats. Evidence indicates attackers have leveraged the flaw to gain root-level access and install cryptocurrency miners on compromised systems. The exploit’s discovery and public demonstration underscore the severity of the threat to Mac users globally.
