AI-Debiased Article
Rewritten from Ars Technica 1 min read
4 Wire-neutral provisional

✓ No loaded language, vague sourcing, or framing detected.

Active Exploitation of High-Severity macOS Vulnerability Reported

A high-severity vulnerability in macOS, tracked as CVE-2026-65400, is under active exploitation, according to Dutch officials. The flaw allows attackers to execute malicious code and has been linked to unauthorized access and the installation of a cryptocurrency miner on affected systems. Apple has released a patch for the vulnerability in recent updates.

Companies
Apple

Dutch officials have reported that a high-severity vulnerability in macOS, which allows attackers to execute malicious code, is currently being exploited. The Netherlands National Cyber Security Centrum (NCSC) indicated that there have been instances of active abuse of this vulnerability on multiple systems where port 5900 was accessible from the Internet. In these cases, unauthorized access to the root of the affected systems was noted, along with the installation of a Monero cryptocurrency miner.

The vulnerability, identified as CVE-2026-65400, received a patch from Apple last week for macOS versions Tahoe, Sequoia, and Sonoma. It has a severity rating of 7.1 out of 10 and is linked to a flaw in the macOS screen sharing feature, which enables remote access to view the screen and control the keyboard and mouse. The issue arises from a bug in the state management system, which tracks user interactions and other system states.

Annotating as

No note attached

on this article.

Original vs. Neutral

Original Headline

Vulnerability giving attackers full control of Macs is under active exploitation

Neutral Headline

Active Exploitation of High-Severity macOS Vulnerability Reported