Apple Urgently Patches Critical Zero-Day Exploit for macOS Screen Sharing Vulnerability
August 18, 2026
Apple released fixes for a critical Screen Sharing flaw across macOS Tahoe, Sequoia, and Sonoma, urging users to update via System Settings and to disable Screen Sharing if not in use.
The vulnerability, tracked as CVE-2026-65400, allowed attackers to gain root access on exposed Macs through the built-in Screen Sharing feature.
Apple’s response spans three security bulletins corresponding to each affected macOS release, signaling a coordinated, cross-version patch effort.
Experts warn that once exploited, attackers may pursue cryptocurrency mining or other payloads and data exfiltration with root access.
The flaw was disclosed earlier in the month, with evidence of a working PoC online about a week before the advisory; the advisory from NCSC-NL highlighted exploitation risk.
Most risk comes from devices reachable via port 5900 on the internet or locally, including home networks, not just exposed servers.
CISA rated the flaw as actively exploited and noted that exploitation can be automated.
Federal guidance rates the flaw as highly critical due to unauthenticated or user-interaction-free exploitation; patching does not undo existing malware or attacker actions.
There is a move toward emergency security releases when zero-day exploitation is confirmed given rapid weaponization.
Patches do not fix machines already compromised; if unsure, wiping and reinstalling is advised.
NCSC-NL confirms the flaw is being actively exploited in the wild, elevating the update’s priority for remote-access users.
Post-compromise activity seen elsewhere includes installing persistent SSH keys and mining malware, modifying logs, and launching LaunchDaemons to survive reboots.
Summary based on 5 sources
Get a daily email with more Tech stories
Sources

ExtremeTech • Aug 18, 2026
Update Your Mac ASAP to Avoid This Screen Sharing Bug
TechSpot • Aug 19, 2026
Apple just patched a critical macOS flaw that let hackers break in without a password
iThinkDifferent • Aug 19, 2026
Safari 26.6.1 Patches 21 WebKit Flaws, Screen Sharing Zero-Day Already Exploited