The Mac remote-control setting attackers are using right now
If your business runs Macs, there is a remote-control feature built into every one of them that you may have switched on years ago and forgotten. This week it became the way attackers are getting in. A flaw in macOS Screen Sharing lets someone on the network take control of a Mac without knowing any password, and it is already being used in the wild to install software that quietly mines cryptocurrency using your machines, with the highest level of access on the system.
What the flaw is
Screen Sharing is the built-in macOS feature that lets one Mac view and control another over the network. It listens on a technical address known as port 5900. The flaw, tracked as CVE-2026-65400 and rated 9.8 out of 10 for severity, is an authentication bypass: an attacker who can reach that port can connect to Screen Sharing without valid credentials. Once connected, they can see and control the Mac exactly as the feature is designed to allow, because that is precisely what the feature does.
Apple fixed the problem on 6 August in three updates: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Any Mac on an older version of those releases is affected.
It is not theoretical
The Netherlands' National Cyber Security Centre issued a warning after being told of real incidents. In every case the agency saw, the attacker gained root access, the top level of control on a Mac, and installed a Monero cryptominer. Monero is a cryptocurrency that can be mined on any ordinary processor, so a compromised Mac becomes free computing power for the attacker, which shows up as a machine running hot and slow for no obvious reason.
Cryptomining is the visible symptom, not the ceiling. Root access means an attacker could just as easily steal saved passwords and keys, plant malware that survives a restart, read business files, and move sideways onto other machines on the same network. The mining is simply the easiest thing to turn into money today.
Who is actually exposed
The real risk sits with Macs that can be reached from the internet on port 5900. That usually happens one of three ways: a router set up to forward that port to a Mac inside the office, a Mac given its own public address, or a hosting or cloud setup that exposes it. Those are the machines being hit right now, so they are the ones to check first.
A Mac reachable only from inside your own office network is not in the clear, but an attacker would first have to get a foothold on that network. Given how many other routes onto a network exist, from a phishing email to an infected laptop, "only reachable internally" is a reason to patch this week rather than a reason to relax.
What to do
Update the affected Macs. This is the fix. On each Mac, open the Apple menu, choose System Settings, then General, then Software Update, and install what it offers. Aim to be on macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 or later. If you use a tool or a supplier to manage your Macs, tell them to push these versions now.
If you cannot update immediately, turn Screen Sharing off. In System Settings, go to General, then Sharing, and switch Screen Sharing off if you are not deliberately using it. While you are there, turn off Remote Management too unless you rely on it, because it is a second route to the same kind of remote control.
Check whether port 5900 is open to the internet. If your network has a Mac that outside machines can reach directly, close that off at the router or firewall unless there is a genuine, controlled reason for it. This is the single change that most reduces the risk, and it is worth doing regardless of the patch. If a supplier looks after your network, ask them plainly: is Screen Sharing on any of our Macs reachable from the internet, and if so, why.
Assume a machine that was exposed may already be affected. If a Mac was reachable on port 5900 and running an old version, treat it as potentially compromised rather than assume you were lucky. A machine running hotter or slower than usual is a reason to look closer, not to ignore it.
How Steelwise can help
Working out which of your machines are quietly reachable from the internet, and closing those routes without disrupting the people who use them, is the kind of security review we do. Get in touch.
Further reading
- Apple: About the security content of Apple software updates
- Apple: How to update macOS
- NCSC: Keeping devices and software up to date