Apple users running Macs are being urged to install the latest security updates after officials in the Netherlands confirmed that hackers are actively exploiting a serious flaw in the operating system's built-in remote access tool.

A password-free way in

The vulnerability sits in Screen Sharing, the macOS feature that lets one Mac remotely view and control another over a network, similar in purpose to Windows' Remote Desktop. Screen Sharing works using VNC, a decades-old remote-control protocol, and the affected setups accept connections on network port 5900.

According to Ars Technica, the flaw allows an attacker on the network to authenticate to Screen Sharing without knowing the correct username or password, effectively bypassing the login screen entirely. Researchers who reverse-engineered Apple's patch, publishing their findings on the social platform X, described how the bug let any network attacker log in as any account without knowing the password.

Once inside, an intruder can view the screen, control the keyboard and mouse, open applications, browse files and change security settings, much as if they were sitting at the keyboard themselves, according to reporting by BleepingComputer. The flaw is tracked as CVE-2026-65400 and carries a severity score of 7.1 out of 10, a rating security teams generally treat as high risk.

Dutch warning follows real-world attacks

The Netherlands' National Cyber Security Centre, the government body that coordinates cyber defence for the country, issued the alert after receiving reports of exploitation in the wild. The agency said it had received a notification indicating that active abuse of this vulnerability had been observed on multiple systems where port 5900 was accessible from the internet.

"In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed," the NCSC said, according to BleepingComputer.

Root access is the highest level of control on a Unix-based system such as macOS, giving an attacker the ability to read, modify or delete essentially anything on the machine. In the incidents observed so far, that access was used to install software that mines the cryptocurrency Monero, a task that generates money for the attacker but otherwise causes little visible disruption, which may explain why victims might not notice anything is wrong.

Who is affected, and what to do

Apple issued fixes on 6 August, releasing macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9 for its three most recent supported versions of the operating system. Apple's advisory describes the fix as improved state management designed to enforce correct credential checks, and credits security researcher Alfredo Pesoli with reporting the issue.

The risk applies specifically to users who have manually switched on Screen Sharing, a feature that is turned off by default on Macs. For most home and office users, whose Macs sit behind a router and are not directly reachable from the open internet, the practical danger is lower. The greater concern is for small businesses, universities or individuals who have configured port forwarding or otherwise exposed the service publicly, often to allow remote work access.

Security researchers, including analysts at the threat intelligence firm Huntress, recommend that anyone using Screen Sharing update immediately, disable the feature when it is not actively needed, and avoid exposing port 5900 directly to the internet. A safer alternative for remote access is to connect through a VPN or an SSH tunnel, which encrypts and authenticates the connection before Screen Sharing traffic is ever exposed.

For European organisations already navigating stricter cyber security reporting obligations under the EU's NIS2 directive, the episode is a reminder that even mainstream consumer operating systems can carry enterprise-grade risks when convenience features are left open to the wider internet.

This article is free to read. It always will be — no paywall, no account, no tracking.