Published
- 18 min read
The Mac Screen-Sharing Flaw and the Door Your Router May Have Left Open
Stay Safe Online Without Making It Your Second Job
The Digital Fortress (Second Edition)
A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest.
For People Who Cannot Afford to Get Privacy Wrong
The Anonymity Playbook (Second Edition)
A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails.
Write, Ship, and Maintain Code Without Shipping Vulnerabilities
Secure Software Development
A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory.
Use AI Coding Agents Without Losing Control of Your Codebase
The Secure Harness
A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates.
Stop Shipping Demos. Start Shipping Systems.
The AI Native Engineer
Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature.
A Mac can sit quietly on a desk and still have a front door facing the public internet. You may never have opened it yourself. A remote-support session from years ago, a router setting copied from an old guide, or a small office setup that nobody revisited can leave Screen Sharing reachable from outside the building.
That particular door matters this week. On 13 August 2026, the Netherlands’ National Cyber Security Centre said it had received a report of active abuse of a flaw in macOS Screen Sharing. Attackers reached multiple Macs whose Screen Sharing port was accessible from the internet, gained the highest level of control on those machines, and installed software that mines Monero cryptocurrency. Apple had released fixes on 6 August.
Here is the reassuring part. The reported attacks need a particular combination: a vulnerable Mac, Screen Sharing switched on, and the relevant route from the internet left open. Most home routers block unsolicited incoming connections unless somebody changes that behaviour. Installing the current macOS update closes the software flaw, and turning off Screen Sharing closes the service when you do not need it. You can do both checks in a few minutes.
The useful lesson lasts longer than this patch. Remote access is a spare key to your computer. Keeping that key in a drawer for the day you need it is sensible. Leaving the door unlocked all year because a helper might visit one afternoon is not.
What happened, and what has actually been confirmed
Apple released macOS Tahoe 26.6.1 on 6 August 2026. Its security notice describes CVE-2026-65400 as an authentication problem in Screen Sharing and says an attacker on the network may be able to sign in without valid credentials. Apple says it fixed the problem by improving how the service keeps track of its state during a connection. Corresponding fixes are available in macOS Sequoia 15.7.9 and Sonoma 14.8.9, according to the National Vulnerability Database entry.
That wording sounds abstract, so picture a receptionist checking visitors at several doors. A normal visitor presents a name and password, the receptionist confirms both, and only then marks the visit as approved. A state-management bug means the receptionist can lose track of which check belongs to which visitor. Carefully ordered messages can make the process arrive at the approved state without a valid password ever being accepted.
The Dutch NCSC first warned organisations about the vulnerability on 7 August. On 13 August it updated the alert after receiving a report of active abuse on multiple systems. The agency names two conditions beyond an unpatched Mac: Screen Sharing had to be enabled, and TCP port 5900 had to be reachable from the internet. In the reported cases, an attacker obtained root access and placed a Monero miner on the machine. Root is the Mac’s master key, with far more power than an ordinary user account.
Independent reporting agrees on those core facts. Ars Technica reported on 14 August that the observed systems exposed port 5900 and that Apple had patched Tahoe, Sequoia, and Sonoma. The Hacker News reported on 15 August that the available public details do not establish when the attacks began, how broad the campaign is, or whether attackers have installed anything beyond miners. Those unknowns are worth preserving. “Actively exploited” tells us the flaw has moved from theory to use; it does not tell us that every Mac owner is being hunted.
You may see two severity numbers in coverage. The NCSC’s original notice gave the flaw 7.1 out of 10, while the CISA-contributed score now displayed by NVD is 9.8. The higher assessment assumes a network attacker needs no privileges or user click and can have a complete effect on confidentiality, integrity, and availability. The difference reflects changing technical assessment, not two separate flaws. For a person deciding what to do on Sunday morning, the score is less useful than the plain conditions: update the Mac, and do not leave Screen Sharing open to the internet.
How a local sharing tool becomes an internet entrance
Screen Sharing is built into macOS so one computer can view and control another. It can be handy when a family member needs help, when an employee works on a Mac in another room, or when an administrator looks after a small group of machines. Apple places its switch under System Settings, General, Sharing. When enabled, it listens for remote-control connections using the long-established VNC system, normally on TCP port 5900.
Inside a home or office network, devices often have private addresses that the wider internet cannot call directly. The router sits between them and the public connection. Think of it as the building’s front desk: outgoing requests are allowed to leave, replies are sent back to the right room, and unexpected visitors do not automatically get a room number. This ordinary router behaviour is why switching on a local sharing service does not always make it public.
A port-forwarding rule changes that arrangement. It tells the router that visitors arriving at a particular public door should be sent to one device inside. People add such rules for remote desktop, game servers, cameras, storage boxes, and home-lab projects. Some software and routers can also negotiate openings automatically through features such as UPnP. The convenience is real, but so is the consequence: a service designed for a trusted local network may become reachable by anyone who can find the public address.
The Mac’s own firewall is another layer, though it should not carry the whole burden. As Ars Technica explains, enabling Screen Sharing opens the service on the Mac while routers generally continue to block outside access unless configured otherwise. A router rule can bridge that outside connection inward. A business firewall may make the same choice deliberately for remote administration. Once the route exists, the Screen Sharing service has to reject strangers correctly. CVE-2026-65400 broke that final identity check on unpatched systems.
This is why “I have a router” and “I use a firewall” are incomplete answers. A locked front door helps only while it remains locked. The useful check is whether port 5900 is deliberately exposed, who made that decision, and whether the decision still serves a real need. Many stale openings survive because the person who created them solved an immediate problem and never put closure on the calendar.
The same pattern appears beyond Macs. A network storage box, security camera, development dashboard, or smart-home controller can be quite reasonable inside your home and reckless on the public internet. The product name changes; the boundary question stays the same. Does the whole internet need to reach this service, or can the few people who need it enter through a safer private route?
What the miner tells us, and what it does not
The malware seen in the Dutch report used compromised Macs to mine Monero. Cryptocurrency mining performs repeated calculations in the hope of earning digital currency. On somebody else’s computer, the attacker collects any reward while the owner pays through electricity, heat, fan noise, battery wear, and slower work. A miner is easy to understand because its appetite can become visible.
That visible outcome should not narrow the response too much. The important fact is the reported root access that came first. An intruder holding the master key could choose a miner, a password thief, a hidden remote-control tool, or a foothold for later use. Current public reporting has not confirmed those other payloads in this campaign. They are possible consequences of the access level, not claims about what these attackers have already done.
There is also no public number for the total affected population in the NCSC alert. It says multiple systems, not thousands or millions. The Hacker News reports a researcher’s separate scan claim about open Screen Sharing hosts, but that claim does not establish how many were vulnerable, compromised, or connected to this campaign. Combining an internet scan with an incident report can make a frightening headline while answering none of those questions. We do not need the inflated version to justify installing a security update.
A slow Mac does not prove infection either. Browser tabs, video calls, photo indexing, software updates, and an ageing battery can all produce heat and high processor use. Activity Monitor may show an unfamiliar process without telling an ordinary user whether it is malicious. Guessing from one symptom often creates more anxiety than evidence.
If your Mac was never reachable from the internet on port 5900, this specific attack route was absent even before you patched. If Screen Sharing was enabled only on your private home network, the flaw still deserved its update, but the observed public-internet condition was missing. If you know that port 5900 was forwarded to an unpatched Mac, treat that machine differently: close the route, update it, and have a competent person check it rather than relying on a quick glance at processor usage.
The distinction matters because good security work follows exposure. A person with a closed service needs a patch and a settings check. A small business with a publicly exposed, unpatched service needs an incident review. Giving both people the same twenty-item checklist wastes one person’s evening and understates the other’s problem.
Why the patch and the closed door both matter
Installing the fixed macOS version repairs the faulty identity check. For supported Macs, the safe minimum versions named by Apple and NVD are Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Apple describes Software Update as the normal place to get a compatible release, and its current update instructions direct users to System Settings, General, Software Update.
A closed service removes an entire route. If Screen Sharing is off, there is no reason for its network listener to accept connections. If the router does not send port 5900 inward, strangers on the public internet cannot use that direct path to reach the Mac. Those controls help with mistakes that have not been discovered yet, not just this one assigned number.
People sometimes frame patching and exposure reduction as competing strategies. They solve different parts of the problem. Software updates correct known faults in a service you may genuinely need. Closing an unused service reduces the number of faults you will ever have to care about. Keep both when the service has no everyday purpose.
Changing the Screen Sharing password alone would not have addressed CVE-2026-65400. Apple’s advisory says the weakness allowed authentication without valid credentials. A long password protects a door only when the lock reliably checks it. Two-factor authentication on your Apple Account also does not repair a separate Screen Sharing authentication bug. These are good protections in their own places, but neither substitutes for this macOS update.
Changing port 5900 to an unusual number is weak camouflage. Automated scans can inspect many ports, and a determined visitor does not need the standard label on the door. A private network route, such as a properly configured VPN used by an organisation, can limit who reaches the Screen Sharing service in the first place. That setup may be worthwhile for a business with real remote-administration needs. For a household that uses Screen Sharing twice a year, turning it on for the session and off afterward is simpler.
The permission to skip matters here. You do not need to buy a security product, learn command-line networking, or run an internet scanner to make the ordinary case safer. Update the Mac. Turn off sharing you do not use. Ask for help only if you discover an exposure or business requirement that changes the case.
The five-minute check for a home Mac
Start on the Mac itself. Save your work because the update may need a restart, then use the following sequence. The order closes the unnecessary entrance before asking you to investigate how it was exposed.
-
Install the current macOS update: Open the Apple menu, choose System Settings, select General, and open Software Update. Install the update offered for your Mac. For the three affected supported branches, confirm that the version is at least Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9. If Software Update offers a later version, use that later version.
-
Check Screen Sharing: In System Settings, open General, then Sharing. Apple’s Screen Sharing guide places the control there. If Screen Sharing is on and you do not use it, turn it off. Check Remote Management as well if this is your own home Mac; an employer-managed machine may need that setting, so follow your IT team’s instructions rather than changing company administration tools yourself.
-
Think back to remote help: Ask whether anyone set up direct access to this Mac from outside your home. A family helper, computer shop, former employee, or old work-from-home arrangement may jog your memory. If the answer is no and you have never changed router settings, you can stop after updating and disabling the unused service.
-
Review the router only when there is a reason: If somebody did configure remote access, sign in to the router using the address and instructions printed on it or supplied by your internet provider. Look for Port Forwarding, Virtual Server, NAT, Remote Access, or UPnP mappings. Remove a rule that sends TCP port 5900 to the Mac if the rule is no longer required. Take a photo before changing an unfamiliar business setup, or ask the person who maintains it.
-
Escalate a real exposure: If port 5900 was publicly forwarded to this Mac while Screen Sharing was on and macOS was below the fixed version, disconnect or close that route, finish the update, and seek hands-on help. A small business should preserve relevant router and Mac logs if available and have its IT provider assess the machine. A home user can contact Apple Support or a trusted technician and clearly say, “Screen Sharing on port 5900 may have been exposed before I installed the 6 August security fix.”
That final sentence gives a helper something useful to work with. “My Mac feels hot” invites guesswork. Naming the service, public route, and patch date narrows the investigation.
Automatic updates are worth checking while you are in Software Update. They reduce the time between a fix appearing and your Mac receiving it. A machine used for critical work may still need a planned restart, but repeatedly postponing security releases keeps yesterday’s known doorway available. Pick a time that protects your work, then complete the restart rather than leaving it in a notification tray for weeks.
A different response for a small office
A design studio, clinic, shop, or family business may have Macs that are intentionally reachable for support. The owner may not know which router rules exist because an outside provider set them up. That uncertainty calls for an inventory, not a frantic tour of every menu.
Ask the provider for a plain list of internet-facing services and the machines behind them. The list should identify the public port, the internal destination, why the route exists, who uses it, and when somebody last reviewed it. If Screen Sharing or Remote Management is exposed directly, ask whether access can move behind a private VPN, a device-management system with tightly controlled access, or another brokered support method that does not publish the Mac’s remote-control service to everyone.
Patch every relevant Mac, including machines that spend most of their life in a cupboard or back room. Forgotten devices are common in small organisations because they keep doing one job without asking for attention. A display controller, build machine, media server, or reception Mac can miss the update cycle while remaining powered on. Check the exact version after the restart rather than treating “updates are automatic” as evidence that the update finished.
Then look back across the exposed period. The NCSC updated its alert on 13 August after reports of active abuse, and Apple published the fixes on 6 August. Public details do not give a clean start date for exploitation. If your organisation exposed port 5900 on a vulnerable Mac, choose a review window with your technical provider based on the device’s logs and update history rather than assuming the attack began when the news article appeared.
A useful review asks what changed on the machine, which new programs or launch items appeared, whether unknown accounts or remote-access tools were added, and whether the Mac connected repeatedly to mining infrastructure or other unusual destinations. Root access means a compromised machine can hide from casual inspection. Reinstalling from a known-good state may be the sensible choice when evidence of intrusion exists, especially if that Mac handled customer data, passwords, finances, or software releases.
Credentials used on a confirmed compromised Mac deserve attention after the device is clean. Change important passwords from a different trusted device, revoke active sessions where services provide that option, and replace business keys or tokens that the Mac could read. Do not begin by changing every password on the suspect machine; that can hand fresh credentials to malware still running there.
The office does not need a glossy fifty-page report. It needs an answer to four questions: Was the service public? Was the Mac vulnerable during that time? Is there evidence somebody entered? What trusted state will the business return it to? Those answers determine the work.
Remote help without a permanent open door
Families often enable remote access for a good reason. A parent gets stuck with a printer, a child lives in another city, and seeing the actual screen is faster than describing twelve buttons over the phone. The mistake comes when a temporary support route becomes permanent infrastructure nobody owns.
For occasional help, use a tool or method that requires the person at the Mac to approve the session, keep it current, and close it when the visit ends. If you use Apple’s Screen Sharing only within the same home network, leave it off between sessions unless there is a clear daily need. Avoid publishing port 5900 directly through the router merely to save a few minutes next time.
A business has a stronger case for persistent access, but it also has the resources to make that access private and accountable. The service can sit behind a company VPN, with individual accounts, limited administrators, and records of who connected. Support staff should not share one immortal password. Access should disappear when a contractor leaves or an employee changes role.
Remote administration always trades convenience for reach. The right goal is not zero remote access; many people depend on it. The goal is a narrow entrance used by named people for a known purpose, with a reliable way to close it. Direct exposure to the whole internet is much wider than most homes or small offices need.
This incident also shows why routers belong in ordinary security conversations. People hear “Mac vulnerability” and look only at the Mac. The successful route described by the NCSC crossed both layers: the Mac had a vulnerable service, and the network allowed public traffic to reach it. Fixing either layer breaks that exact path; fixing both leaves less room for the next mistake.
Write down any router rule you decide to keep. A note with the date, purpose, internal device, and responsible person turns a mystery into a decision that can be revisited. Put a review reminder six months ahead. Old openings are rarely malicious choices. They are chores without an owner.
Keep the lesson, then get on with your day
CVE-2026-65400 is a serious flaw in a powerful service, and there is credible evidence of active abuse. The facts support prompt action without supporting panic. The observed route required Screen Sharing to be enabled and port 5900 to be reachable from the internet. Apple has shipped fixes for current Tahoe, Sequoia, and Sonoma versions.
For most people, the response is pleasantly small. Install the update offered by Software Update. Open General, Sharing, and turn off Screen Sharing if you do not use it. If nobody has ever arranged outside remote access to your Mac, you have little reason to turn the evening into a network investigation.
People who discover an old port-forwarding rule or a genuinely internet-facing Mac have a different job. Close the route, patch the system, and get the exposure reviewed with evidence rather than guesswork. Businesses should also replace direct public access with a private, managed route where practical.
The broader habit is worth keeping. Every remote-control feature is a spare door, and every permanent door needs an owner. Use the ones that solve a real problem. Close the rest. You do not need to turn your home into a fortress; you only need to stop lending the whole street a key.
For more calm, practical security guidance, join the Cyber Security in Plain English newsletter. It is one email per month.
Sources
- Apple Support: About the security content of macOS Tahoe 26.6.1, accessed 2026-08-16
- Netherlands National Cyber Security Centre: Kwetsbaarheid in macOS Screen Sharing, accessed 2026-08-16
- National Vulnerability Database: CVE-2026-65400, accessed 2026-08-16
- Ars Technica: Vulnerability giving attackers full control of Macs is under active exploitation, accessed 2026-08-16
- The Hacker News: Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner, accessed 2026-08-16
- Apple Support: Update macOS on Mac, accessed 2026-08-16
- Apple Support: Turn Mac screen sharing on or off, accessed 2026-08-16