A macOS vulnerability that lets attackers take over a Mac’s screen without valid credentials is now being actively exploited, Ars Technica reports, citing a warning from the Netherlands’ National Cyber Security Center.
Apple patched the flaw on August 6 with the release of macOS Tahoe 26.6.1, along with corresponding fixes in macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9.
The vulnerability allowed an attacker to authenticate to macOS’s Screen Sharing feature without valid credentials, effectively enabling them to view the screen and remotely control the keyboard and mouse of a targeted Mac. Apple described the fix as “improved state management.”
The NCSC-NL confirmed it had received reports of the flaw being actively abused, with attacks observed on machines where port 5900 was accessible from the internet.
That port is the one macOS exposes when Screen Sharing is enabled. In every confirmed case, the attackers had gained root access and installed a Monero cryptocurrency miner, using the compromised machine’s processing power to generate digital currency.
Who Is Actually at Risk
Screen Sharing is turned off by default on macOS, which limits the pool of exposed machines to those where a user or administrator has specifically enabled it.
The risk is also more pronounced for Macs directly reachable from the internet, such as those on business or institutional networks with port 5900 open, rather than home computers sitting behind a standard router.
Most home routers block incoming connections to that port unless explicitly configured to forward them. Still, the combination of root-level access and a confirmed active exploitation campaign makes this an update worth prioritizing for anyone who hasn’t installed it yet.
Security researchers have also recommended using a VPN when Screen Sharing is active, even on patched systems, as an additional precaution.
How to Check Your Mac
To confirm your Mac is running the patched version, open System Settings, select General, then Software Update.
The fix applies to all three currently supported macOS versions, so users on Tahoe, Sequoia, and Sonoma all have an update available if they haven’t already installed it.