{"rewrite":{"id":"r_1cf4ca82de8265a8aff2655a","clusterId":"c_645e269a6354228c033eb391","slug":"macos-screen-sharing-flaw-cve-2026-65400-under-active-attack","model":"deepseek-v4-flash:free","headline":"MacOS Screen Sharing Flaw CVE-2026-65400 Under Active Attack","summary":"The Dutch Cyber Security Centre reports that CVE-2026-65400, an authentication flaw in macOS Screen Sharing, is being actively exploited. Attackers can log into any account without a password and gain root access, then install a Monero miner. Apple issued an emergency patch on August 6, 2026.","whyItMatters":"The flaw allows full system compromise without credentials, and active exploits are already installing cryptocurrency miners, making the emergency patch essential for all Mac users.","webCardHtml":"\u003cp\u003eThe Dutch Cyber Security Centre (NCSC-NL) disclosed that CVE-2026-65400 stems from insufficient state management in the authentication process, letting attackers make authentication attempts that normally require valid credentials. In effect, it allowed logging into any account without knowing the password.\u003c/p\u003e\u003cp\u003eSecurity researcher Calif published a proof-of-concept video after reverse-engineering Apple\u0026#39;s emergency update from August 6, 2026, getting an exploit working in about four hours. According to NCSC-NL, every observed exploitation gained root-level access and installed a Monero miner that secretly uses Mac resources. The miner itself causes limited harm, but the same access could steal credentials or install more damaging malware.\u003c/p\u003e\u003cp\u003eApple has distributed a patch. NCSC-NL advises turning on Screen Sharing only when needed.\u003c/p\u003e","blueskyPost":"CVE-2026-65400 in macOS Screen Sharing is under active exploitation. Attackers log in without a password, gain root, and install a Monero miner. Apple patched on Aug 6. Turn Screen Sharing off unless needed.","twitterPost":"CVE-2026-65400 in macOS Screen Sharing is actively exploited: no password needed, root access, Monero miner installed. Apple's Aug 6 patch is out. Disable Screen Sharing when not in use.","threadsPost":null,"newsletterBlurb":"A critical macOS Screen Sharing vulnerability, CVE-2026-65400, is being actively exploited, allowing attackers to log into any account without a password and gain root access. The Dutch Cyber Security Centre reports Monero miners being installed. Apple has issued an emergency patch.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260819-macos-screen-sharing-vulnerability/\",\"title\":\"High-severity attacks exploiting macOS screen sharing vulnerability are occurring frequently\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4556,"outputTokens":552,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1787111864,"createdAt":"2026-08-19T03:51:08.000Z","publishedAt":"2026-08-19T03:51:44.000Z","updatedAt":"2026-08-19T03:51:08.000Z"},"cluster":{"id":"c_645e269a6354228c033eb391","canonicalTitle":"macOSの画面共有関連の脆弱性を悪用した深刻度の高い攻撃が頻発している","representativeArticleId":"a_c54e88c35684ca54a64d27b7","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-18T23:00:00.000Z","lastSeenAt":"2026-08-18T23:00:00.000Z","updatedAt":"2026-08-19T03:51:44.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260819-macos-screen-sharing-vulnerability/","title":"macOSの画面共有関連の脆弱性を悪用した深刻度の高い攻撃が頻発している"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
