Update your Mac: Screen Share vulnerability gives attackers full control of your computer

Apple's latest macOS update consists of a single patch to deal with a critical exploit.
 By 
Matt Binder
 on 
Mysterious hand using MacBook
Apple has released a critical security update for macOS that patches a Screen Share-related vulnerability. Credit: Yuliya Taba via Getty Images

Mac users, if you haven't updated your MacBook or desktop Mac computer in the last week or so, install that latest update now.

The most recent Mac update from Apple includes a patch for a major vulnerability that could allow an attacker to take over a targeted Mac.

The exploit involves an authentication bug in Mac's Screen Share functionality, Ars Technica reported. An unauthorized party can exploit the bug to take control of a user's keyboard and mouse when screen sharing is enabled.


You May Also Like

The vulnerability is being tracked as CVE-2026-65400. Apple's own explanation of the security update warns users that this security issue could allow an attacker on the network to access a Mac without valid credentials.

The Netherlands National Cyber Security Centre (NCSC) warned about the vulnerability last week after the exploit was initially made public.

Cybersecurity firm Calif recently shared how they reverse-engineered Apple's recent macOS patch as it "piqued our curiosity." As Calif explained in a blog post, "Apple does not ship an update out of band unless something is critical."

From there, Calif researchers uncovered the Screen Share vulnerability. The firm posted a video demonstrating the attack.

According to the NCSC report on the vulnerability, the exploit results from "insufficient state management during the authentication process." If Screen Share is activated on a Mac, the macOS firewall exposes port 5900 to third parties over the internet. In turn, unauthorized access can occur via authentication attempts that wouldn't usually be accepted.

The NCSC reports that it has received notice that the exploit has been observed in the wild. The vulnerability has reportedly been used to obtain root access on an affected system. In this case, a Monero crypto miner was installed by the unauthorized user.

The first researcher to discover the exploit found roughly 40,000 Macs with Screen Share enabled and reachable from the internet, which gives a sense of just how many potential targets were out there at any given time.

Apple released the patch last week for macOS Tahoe, Sequoia, and Sonoma. Mac users are urged to install the latest security update.

Matt Binder
Matt Binder
Senior Tech Reporter

Matt Binder joined Mashable's tech vertical in 2018, where he covers social media, tech policy, cybersecurity, online scams, cryptocurrency, AI, creator news, weird tech, and other related tech beats.

Mashable Potato

Recommended For You
Meta’s Muse reportedly has zero-day vulnerability that lets attackers take over your Mac
Meta Muse

This $30 bundle gives your Mac 27 new superpowers
The 27-App Lifetime Mac Bundle

Apple announces new $899 M6 Mac mini and $5,499 M5 Ultra Mac Studio
a woman using the m6 mac mini

Mac mini deal alert: The new Apple Mac mini M5 Pro is $30 off at Amazon
Mac mini M5 Pro on composite background

The new Apple Mac Studios are more powerful than ever. Here's how to preorder ahead of the Sept. 22 launch.
a person sits in front of three computer monitors with the new mac studio on the desktop

Trending on Mashable
'Ted Lasso' just sank to a new low
Jason Sudeikis and Annette Badland in "Ted Lasso."

Wordle today: Answer, hints for October 2, 2026
Wordle game on a smartphone

NYT Connections hints today: Clues, answers for October 2, 2026
Connections game on a smartphone

Apple iOS 27.2 arrives soon: 6 new features on the way
iOS 27