· via Hacker News – Front Page (native)
Actively exploited macOS screen-sharing bug leaves internet-exposed Macs with root and Monero miners
Apple has patched CVE-2026-65400, a macOS screen-sharing flaw the Dutch NCSC says is being exploited on machines with port 5900 exposed, giving attackers root and installing Monero miners.

A high-severity vulnerability in macOS screen sharing is being actively exploited against Macs reachable from the public internet, and Apple has now shipped fixes covering three recent versions of the operating system. The flaw, tracked as CVE-2026-65400 and rated 7.1 out of 10 for severity, was disclosed in an Ars Technica report and retold this week in a Stratechery essay, "Apple and a Hacker's Future," written from the perspective of someone whose machine was actually compromised.
The flaw and the Dutch warning
According to Ars Technica, the bug sits in macOS's screen-sharing capability — the feature that lets a remote party view a Mac's display and control its keyboard and mouse while the machine is powered on. The underlying cause is a defect in the feature's state management, the internal bookkeeping that tracks prior events, user interactions and system variables. Apple patched the vulnerability for macOS Tahoe, Sequoia and Sonoma in the days before the Stratechery piece appeared.
The Netherlands' National Cyber Security Centre issued the warning that put the bug on the map. The centre said it had received a report of ongoing exploitation on multiple systems where port 5900, the standard screen-sharing port, was reachable from the internet, and that in every observed case attackers had gained root on the machine and planted a Monero cryptocurrency miner.
Technical details became public at the Black Hat security conference, along with a video demonstrating the exploit. Apple credited security firm Bynario with reporting the vulnerability, and its advisory said the flaw "may" let an attacker without credentials gain access to a Mac — hedged phrasing that Ars Technica notes is common among vendors even when the circumstances seem to warrant stronger language.
A first-hand account
The Stratechery essay doubles as a post-mortem of a real intrusion. The author's always-on Mac Mini, deliberately kept free of personal data and used only to run the Claude and Codex coding agents, was among the affected machines. The first sign of trouble came from a background monitoring tool that Claude restarts every 30 minutes: when it stopped on schedule, the agent fired off an urgent notification.
Claude then gathered diagnostics on its own initiative, halted command execution, and flagged that the account could now run administrator commands without a password — which it correctly assumed was how the attacker's files had been written. The author went on to use Claude to investigate, tracing the intrusion to a specific four-second window, building a tool to watch for a recurrence, and finally wiping the Mac Mini. All of this happened before the author found the Ars Technica article explaining the vulnerability. The piece argues that a persistently running agent functioned as an early-warning system, a counterpoint to fears about granting agents broad machine access.
Apple tightens Full Disk Access
Running parallel to the patch, Apple's developer site published a note on Full Disk Access in macOS. Apple said some developers use the permission in ways that can expose a user's files, mail, messages and browsing history without the user fully understanding what is being granted, and committed to adding controls so that only a deliberate, explicit user action can confer that level of access. The company tied the change directly to AI agents, warning that the risk grows as agents become more capable and autonomous.
Stratechery's author welcomes neither the hack nor Apple's direction. The essay argues that macOS's permission subsystem, Transparency, Consent and Control, is a poor fit for headless machines running agents: prompts are GUI-only and invisible to software, agents constantly spawn new programs that trigger fresh permission requests, and the prompts cannot be made machine-readable without handing malware a way around them. In the author's telling, this friction indirectly led to the Mac Mini compromise in the first place.
Why it matters
For anyone running a Mac with screen sharing reachable on port 5900, the NCSC's findings are blunt: apply Apple's patch and close the port, because attackers are already using this flaw to take root and install cryptocurrency miners. Beyond the immediate remediation, the episode highlights a collision between macOS's human-centric security model and the emerging class of always-on agent machines. Controls that assume a person is watching the screen can push operators of headless Macs toward exactly the exposed configurations this exploit relied on — and as Apple itself acknowledges, agents with broad disk access raise a separate set of risks that the platform is still figuring out how to govern.
- #macos
- #security
- #apple
- #vulnerability
- #cryptojacking