Apple Urgently Patches Critical Zero-Day Exploit for macOS Screen Sharing Vulnerability

August 18, 2026
Apple Urgently Patches Critical Zero-Day Exploit for macOS Screen Sharing Vulnerability
  • Apple released fixes for a critical Screen Sharing flaw across macOS Tahoe, Sequoia, and Sonoma, urging users to update via System Settings and to disable Screen Sharing if not in use.

  • The vulnerability, tracked as CVE-2026-65400, allowed attackers to gain root access on exposed Macs through the built-in Screen Sharing feature.

  • Apple’s response spans three security bulletins corresponding to each affected macOS release, signaling a coordinated, cross-version patch effort.

  • Experts warn that once exploited, attackers may pursue cryptocurrency mining or other payloads and data exfiltration with root access.

  • The flaw was disclosed earlier in the month, with evidence of a working PoC online about a week before the advisory; the advisory from NCSC-NL highlighted exploitation risk.

  • Most risk comes from devices reachable via port 5900 on the internet or locally, including home networks, not just exposed servers.

  • CISA rated the flaw as actively exploited and noted that exploitation can be automated.

  • Federal guidance rates the flaw as highly critical due to unauthenticated or user-interaction-free exploitation; patching does not undo existing malware or attacker actions.

  • There is a move toward emergency security releases when zero-day exploitation is confirmed given rapid weaponization.

  • Patches do not fix machines already compromised; if unsure, wiping and reinstalling is advised.

  • NCSC-NL confirms the flaw is being actively exploited in the wild, elevating the update’s priority for remote-access users.

  • Post-compromise activity seen elsewhere includes installing persistent SSH keys and mining malware, modifying logs, and launching LaunchDaemons to survive reboots.

Summary based on 5 sources


Get a daily email with more Tech stories

More Stories