A critical macOS screen sharing vulnerability, CVE-2026-65400, allows remote attackers to gain root access. Update your Mac immediately to protect your system.
Based on reporting by Ars Technica. Research, structure, and fact-checking by Groundwork.

The CVE-2026-65400 vulnerability allows attackers to take full control of your Mac via the screen sharing feature. To stay safe, update your macOS to the latest version immediately and disable screen sharing if you do not strictly require remote access.
“This vulnerability highlights the danger of exposing legacy management ports like 5900 to the public internet. Even with patches, users should adopt a 'zero-trust' approach to remote access by utilizing VPNs rather than direct port forwarding.”
A critical macOS security flaw, tracked as CVE-2026-65400, allows unauthorized remote attackers to gain full root access to your computer. This vulnerability exists within the macOS screen sharing feature, which enables remote control of your keyboard, mouse, and display. If left unpatched, attackers can execute malicious code, such as cryptocurrency miners, on your system.
According to the Netherlands National Cyber Security Centrum (NCSC), this vulnerability is currently being actively exploited in the wild, particularly on systems where port 5900 is exposed to the public internet (NCSC, 2026). The flaw carries a severity rating of 7.1 out of 10, indicating a high risk to user data and system integrity.
CVE-2026-65400 is a high-severity security flaw in the macOS screen sharing subsystem that permits remote code execution with root privileges. The vulnerability stems from a state management error, where the system fails to properly track and validate user interactions and system events, allowing an attacker to bypass security controls and seize control of the machine (Ars Technica, 2026).
When a Mac has screen sharing enabled and is accessible via port 5900, an attacker can exploit this state management bug to gain the highest level of system access. Once root access is achieved, an attacker can install persistent malware, such as the Monero crypto miners observed by Dutch authorities, or steal sensitive personal information stored on your device.
Your Mac is primarily at risk if you have the Screen Sharing feature enabled and your network configuration allows incoming connections from the public internet. While most home routers block incoming traffic by default, users who have manually configured "port forwarding" to allow remote access to their Mac from outside their home network are the most vulnerable.
To check your current settings:
Apple has released security patches to address CVE-2026-65400 for macOS Tahoe, Sequoia, and Sonoma. Updating your operating system is the most effective way to eliminate the vulnerability. You should prioritize installing these updates immediately to ensure your system state management is secure and protected against unauthorized remote access.
Follow these steps to update your Mac:
If you believe your system has been accessed by an unauthorized party, you should perform a security audit and reset your credentials. Because this vulnerability grants root access, attackers can potentially install persistent backdoors that remain even after a software update. If you detect suspicious performance, such as high CPU usage or unknown background processes, it is safest to back up your essential data and perform a clean install of macOS.
To mitigate ongoing risks, change your passwords for any sensitive accounts you accessed while the system may have been compromised. Additionally, verify that no unauthorized remote management tools were added to your login items or system launch agents. If you are unsure about your system's integrity, consult a professional IT security service to perform a forensic scan.
Your Mac is significantly less vulnerable if screen sharing is disabled. The exploit specifically targets the screen sharing service, so turning it off in your System Settings removes the primary attack vector for this specific vulnerability.
Click the Apple icon in the top-left corner of your screen and select 'About This Mac.' A window will appear displaying your current macOS name and version number. Ensure this version matches the latest release provided by Apple.
No, this specific vulnerability is isolated to the macOS screen sharing subsystem. While iOS and iPadOS have their own security protocols, they do not share this specific screen sharing architecture with macOS.
Port 5900 is the standard network port used by the VNC (Virtual Network Computing) protocol, which enables screen sharing. Exposing it to the internet allows any device worldwide to attempt to connect to your Mac, increasing the risk of unauthorized access.
Tech & Privacy Analyst
Tech & privacy analyst covering smart-home security, data ownership, and AI tools. Sofia benchmarks products against real threat models and total cost.
Is the new Google Pixel hardware worth the upgrade? We break down the latest Gemini AI features, camera processing, and watch updates to help you decide.
Comparing the Google Pixel 11 and Samsung Galaxy S26. Learn how these Android flagships differ in performance, battery life, and price to make the right choice.
Discover how the Unitree G1 humanoid robot is becoming a viral influencer, the technology behind its conversational AI, and what this means for the future.