iOS 26

iPhone

iPad

Apple Watch

AirPods

Apple Deals

Mac Owners Who Skipped Apple’s Latest Update Now Have a Much Bigger Reason to Install It After Real-World Attacks Were Found

Gotechtor select and review products independently. When you purchase through our links, we may earn a commission. See our ethics statement.

A macOS vulnerability that lets attackers take over a Mac’s screen without valid credentials is now being actively exploited, Ars Technica reports, citing a warning from the Netherlands’ National Cyber Security Center.

Apple patched the flaw on August 6 with the release of macOS Tahoe 26.6.1, along with corresponding fixes in macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9.

The vulnerability allowed an attacker to authenticate to macOS’s Screen Sharing feature without valid credentials, effectively enabling them to view the screen and remotely control the keyboard and mouse of a targeted Mac. Apple described the fix as “improved state management.”

The NCSC-NL confirmed it had received reports of the flaw being actively abused, with attacks observed on machines where port 5900 was accessible from the internet.

That port is the one macOS exposes when Screen Sharing is enabled. In every confirmed case, the attackers had gained root access and installed a Monero cryptocurrency miner, using the compromised machine’s processing power to generate digital currency.

Also: Apple may have found a way to make Fitness+ harder to quit, and it’s something Peloton figured out a long time ago

Who Is Actually at Risk

Screen Sharing is turned off by default on macOS, which limits the pool of exposed machines to those where a user or administrator has specifically enabled it.

The risk is also more pronounced for Macs directly reachable from the internet, such as those on business or institutional networks with port 5900 open, rather than home computers sitting behind a standard router.

Most home routers block incoming connections to that port unless explicitly configured to forward them. Still, the combination of root-level access and a confirmed active exploitation campaign makes this an update worth prioritizing for anyone who hasn’t installed it yet.

Security researchers have also recommended using a VPN when Screen Sharing is active, even on patched systems, as an additional precaution.

Also: Tim Cook was asked how he wants to be remembered after 15 years running Apple, and his answer had nothing to do with Apple

How to Check Your Mac

To confirm your Mac is running the patched version, open System Settings, select General, then Software Update.

The fix applies to all three currently supported macOS versions, so users on Tahoe, Sequoia, and Sonoma all have an update available if they haven’t already installed it.

🍎 The only 5 Apple stories that matter — sent every Friday to 50K+ smart readers. You in?

Founder & Editor-in-Chief

Herby has a healthy obsession with all things Apple, especially the iPhone. He loves to rip things apart to see how they work. He is responsible for the editorial direction, strategy, and growth of Gotechtor.

Herby Jasmin

's latest stories

Leave a Comment

Be kind. Discriminatory language, personal attacks, promotion, and spam will be removed. Please read Gotechtor's Community Guidelines before participating.