A dangerous bug in macOS allows you to remotely control other people’s Macs without a password

A dangerous bug in macOS allows you to remotely control other people’s Macs without a password

A Dangerous Bug In MacOS Allows You To Remotely Control

Last week, Apple released updates for macOS Tahoe, Sequoia and Sonoma systems, which fixed the vulnerability CVE-2026-65400, with a score of 7.1 out of 10. It is related to a bug in the macOS screen sharing feature, which allows remote users to view the computer screen and control the keyboard and mouse.

The vulnerability is related to the state management component, which tracks previous events, user actions, variable values, and other system state parameters. Details of CVE-2026-65400 were disclosed at last week’s Black Hat conference. Apple admits vulnerability “perhaps” Allows an attacker without credentials to access the computer.

The computer is vulnerable if port 5900 for remote access is open – this port is opened automatically when screen sharing is enabled. Routers and external firewalls usually block this unless this setting is overridden. Security experts generally recommend keeping it turned off on Mac computers, even if you are using screen sharing and connecting through a VPN or SSH tunnel.

The safest option is to lock screen sharing, enable it only when needed, and turn it off when the session ends. Also, it is recommended to install the latest security updates. Currently, this vulnerability is only known to be exploited for hidden mining of the Monero cryptocurrency. However, it can also be used to install other malware that can steal credentials or perform more dangerous actions on the victim’s computer.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version