Apple · AMD · ARM · Tom's Hardware
Critical macOS Screen Sharing flaw gives attackers remote root access
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
◌ Single Source
The Dutch National Cyber Security Centre (NCSC-NL) reported on August 12 that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing, to compromise Macs with port 5900 exposed to the Internet.
Key facts
- The Dutch National Cyber Security Centre (NCSC-NL) reported on August 12 that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing, to compromise Macs
- The August 6 update comes 10 days after Apple’s July 27 security round and fixes only this single CVE, representing the second Screen Sharing patch in a month
- NVD's change log for CVE-2026-65400 shows CISA initially scored the bug at 7.1 on August 6, using a vector that assumed an attacker needed low-level privileges and could achieve only partial impact
- On August 14, the agency replaced that vector with one requiring no privileges and granting full compromise of confidentiality, integrity, and availability, raising the score to 9.8
Summary
Ryzen to the top: How AMD innovated in the gaming CPU market. NCSC-NL first flagged the vulnerability in an advisory on August 7, a day after Apple's patch, urging organizations to update immediately. Technical details of the bug were presented at last week's Black Hat conference, according to Ars Technica, alongside a video of the exploit in action. NVD's change log for CVE-2026-65400 shows CISA initially scored the bug at 7.1 on August 6, using a vector that assumed an attacker needed low-level privileges and could achieve only partial impact.