A screen sharing vulnerability , which was patched by Apple this month, is already being actively exploited, according to the Dutch National Cyber Security Center ( NCSC-NL ). The macOS vulnerability has raised concerns among the user community and security experts, as it allows attackers to gain remote access to systems without the need for valid credentials.

On August 6, Apple released macOS Tahoe 26.6.1, an update to the macOS Tahoe operating system released last year. The update came just over a week after the release of macOS Tahoe 26.6 , underscoring the urgent need to fix the vulnerability. The vulnerability allowed an attacker to authenticate to Screen Sharing without valid credentials, allowing them to view a Mac's screen and remotely control the keyboard and mouse.
See also: Chinese RAM supplier refuses Apple's offer for cheaper RAM
NCSC-NL said it had been made aware of the vulnerability being exploited, which was observed on multiple systems where port 5900 was accessible from the internet. This port is intentionally exposed by the macOS firewall when screen sharing is enabled, making the systems vulnerable to attacks. Hackers exploited this vulnerability to gain root access to the affected systems and install a Monero crypto miner, using the targeted Mac's resources to mine cryptocurrencies.
Apple macOS: Fix screen sharing vulnerability
Apple, when releasing the fix, said it addressed the issue with “improved state management.” The fix was also included in the updates macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9. Users who have not updated their Macs are urged to do so as soon as possible, as a delay in applying the update could leave their systems vulnerable to attacks.

Even for those who have already updated, it is recommended to use a VPN when screen sharing is active. This adds an extra layer of protection, hiding the user's IP address and making it more difficult for attackers to access the system. Using a VPN can prevent the exploitation of other potential vulnerabilities that may exist in the system.
See also: Apple's corporate espionage lawsuit against OpenAI is not the first
This vulnerability highlights the importance of regularly updating operating systems and security applications. Users should be vigilant and ensure that their systems are always up to date with the latest software versions. In addition, enabling security features, such as a firewall and using strong passwords, can reduce the risk of exploiting vulnerabilities.
This case is a reminder for technology companies to remain vigilant and react quickly to reports of vulnerabilities. The speed with which Apple released the fix shows its commitment to the security of its users, but also highlights the need for continuous monitoring and improvement of security systems.
See also: 'CrashStealer' malware mimics Apple tool and targets Macs
If you're not sure what version of macOS you have, you can check by going to your Mac's System Preferences and selecting General ➝ Software Update . Regularly checking for and promptly applying security updates is critical to protecting your data and systems from malicious attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
