Active Exploitation of macOS Screen Sharing Vulnerability (CVE‑2026‑65400) Enables Unauthorized Root Access and Cryptomining
What It Is – A flaw in macOS Screen Sharing (CVE‑2026‑65400) lets an attacker authenticate without valid credentials, obtain root privileges, and install a Monero cryptominer. Apple released patches for macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, but threat actors began exploiting the vulnerability within days of the advisory.
Exploitability – Public proof‑of‑concept code is available; multiple active attacks have been reported on systems with port 5900 exposed to the Internet. CVSS not disclosed, but the ability to gain root access classifies the risk as High.
Affected Products – Apple macOS Sequoia, macOS Sonoma, macOS Tahoe (all versions prior to the listed patches).
Why It Matters for Compliance & Audit Readiness –
- SOC 2 Access Control criteria require documented mechanisms that prevent unauthorized logins; a bypass of Screen Sharing directly violates the CC6.1 and CC6.2 controls.
- Continuous evidence of patch management and network segmentation is essential to demonstrate due diligence during a SOC 2 audit.
- Enterprise buyers increasingly demand proof that remote‑access services are hardened and monitored, making this exploit a red flag for third‑party risk assessments.
Recommended Actions –
- Verify that all macOS endpoints are running the latest patches (Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1) or later.
- Immediately disable Screen Sharing on systems that cannot be patched, using System Settings → General → Sharing.
- Block inbound TCP 5900 at the perimeter firewall and enforce network‑level segmentation for remote‑desktop services.
- Deploy endpoint detection and response (EDR) rules to alert on unexpected root‑level processes and cryptomining binaries.
- Log all Screen Sharing sessions and correlate with identity‑provider logs to prove that only authorized users accessed the service.
Source: Help Net Security – Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer