Apple's macOS Screen Sharing Flaw Is Being Exploited in the Wild - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Apple's macOS Screen Sharing Flaw Is Being Exploited in the Wild

The screen sharing flaw that Apple rushed out a fix for earlier this month has already been exploited in the wild, according to the Netherlands' National Cyber Security Center (NCSC-NL).

macOS Tahoe Finder Bug Underscores Apples Slipping UI Polish Feature
On August 6, Apple released macOS Tahoe 26.6.1, an update to the ‌macOS Tahoe‌ operating system that came out last year. The update came a little over a week after Apple released macOS Tahoe 26.6.

In its security support document, Apple said that the update addressed a vulnerability that could allow an attacker to authenticate to Screen Sharing without valid credentials – in short, a bad actor could view a user's Mac screen and remotely take control of their keyboard and mouse. It appears however that hackers have already been taking advantage of the flaw.

As first reported by ArsTechnica, the NCSC-NL said that it had been notified of abuse of the vulnerability, "observed on multiple systems on which port 5900 was accessible from the internet." The reason is that when screen sharing is enabled, macOS's firewall intentionally exposes this port.

"In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed," the NCSC-NL added. In other words, a targeted Mac's resources are used to mine cryptocurrency.

When pushing the fix – which was also included in macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9 – Apple said it had addressed the authentication issue with "improved state management." Users who have not updated their Macs should do so as soon as possible. Even for those who have updated, use of a VPN is also recommended when screen sharing is active.

If you're not sure if your macOS version is up-to-date, you can check by going into your Mac's System Settings and selecting General ➝ Software Update.

Popular Stories

iOS 27 Next to iPhone

Here's When iOS 27 Rolls Out Today in Every Time Zone [Update: It's Out]

Sunday September 13, 2026 3:00 am PDT by
Update 10:04 a.m.: iOS 27 is rolling out now, though it may take a bit for all users to see it, so keep checking! Apple is about to release iOS 27, which will finally deliver more advanced Siri AI capabilities as well as a variety of other refinements, improvements, and new features to iPhones. It's Apple's biggest software update of the year, and Apple announced at Wednesday's iPhone event...
iOS 27 Icon iPhone

iOS 27 Available Now With These 8 New Features

Monday September 14, 2026 9:00 am PDT by
Update — 10 a.m. Pacific Time: Apple has released iOS 27. During its iPhone 18 Pro and iPhone Duo event last week, Apple announced that iOS 27 will be released widely on Monday, September 14. iOS 27 should be available around 10 a.m. Pacific Time / 1 p.m. Eastern Time today via the Settings app, under General → Software Update. Below, we have highlighted eight new features and...
Apple iCloud Plus expansion hero

iCloud+ Now Includes Apple TV, Apple Arcade, and Curated Apple Music Stations in Over 100 Countries

Tuesday September 15, 2026 1:43 am PDT by
Apple today announced a new subscription initiative that turns paid iCloud+ subscriptions into a broader services bundle in more than 100 countries. In select countries, Apple says every paid iCloud+ plan, including the cheapest 50GB tier, now includes Apple TV and Apple Arcade "at no additional cost," while family sharing extends the storage, TV and Arcade access to up to five people....

Top Rated Comments

jchap Avatar
4 weeks ago

personal alternative: never installing Tahoe to begin with
The fix was also required and issued for Sonoma and Sequoia; it is not particular to Tahoe.
Score: 32 Votes (Like | Disagree)
chucker23n1 Avatar
4 weeks ago

Does the vulnerability persist if Screen Sharing is Off?
No.


Note that Apple generally leaves every possible "daemon" or "service" running regardless of whether it is being used / turned off.
It's the opposite: they generally design their daemons such that they only run when a socket is open. That's also true of screensharingd. You can easily try this yourself:

[LIST=1]
* With Screen Sharing disabled, open Activity Monitor, and search for screensharingd. You probably won't find it.
* Now in Terminal, do telnet localhost 5900. This will fail with "connection refused", as there's nothing listening. screensharingd still won't be running, of course.
* Now turn it on. Notice that screensharingd still isn't running!
* Finally, try telnet localhost 5900 again. This time, it'll work, and the very act of connecting to that port is what actually launches the daemon.

This is a mechanism in launchd with security and energy benefits. Instead of having screensharingd constantly listening for connections, launchd does the listening:

<key>Sockets</key>
<dict>
<key>Listener</key>
<dict>
<key>Bonjour</key>
<string>rfb</string>
<key>SockServiceName</key>
<string>vnc-server</string>
</dict>
</dict>




1) Enable Firewall (which for some reason defaults to off despite all the kabuki theater of Apple security)
I don't think that would do anything useful in this scenario. If you don't want Screen Sharing to accept connections, just leave it off. If you do, you'll also need to let the firewall allow it in.


3) Ensure everything in Sharing is off as well as all options under them (belts and suspenders people belts and suspenders)
Sure, but that's the default anyway.
Score: 13 Votes (Like | Disagree)
4 weeks ago
Of note: the default setting for Screen Sharing is OFF on macOS. So, unless you've specifically switched it on AFAIK you're not vulnerable to this particular exploit.
Score: 8 Votes (Like | Disagree)
4 weeks ago

How vulnerable is a computer behind a cable modem, etc. with a local IP address (10.0.*.*, 192.168.*.*)?
I would like to know that too. Most internet routers should block incoming connections from the Internet by default. Unless you explicitly forward all (or selected) ports to your Mac of course. But the article above is very not clear about that.
Score: 7 Votes (Like | Disagree)
Steve Adams Avatar
4 weeks ago

Which are?
Linux and Windows.....
Score: 6 Votes (Like | Disagree)
4 weeks ago
As I suggested in the other thread Apple should backport this fix to 10.14 and later (if needed) since those OSes are in active use. If they’re not vulnerable Apple should communicate that. They now leave open a very serious security issue that’s easy to exploit and gives a bad actor instant root access. That’s very, very bad.
Score: 6 Votes (Like | Disagree)