Apple's macOS Screen Sharing Flaw Is Being Exploited in the Wild - MacRumors
Skip to Content

Apple's macOS Screen Sharing Flaw Is Being Exploited in the Wild

Apple's 'Surprise and Shine' iPhone Event: Follow along with our live blog.

The screen sharing flaw that Apple rushed out a fix for earlier this month has already been exploited in the wild, according to the Netherlands' National Cyber Security Center (NCSC-NL).

macOS Tahoe Finder Bug Underscores Apples Slipping UI Polish Feature
On August 6, Apple released macOS Tahoe 26.6.1, an update to the ‌macOS Tahoe‌ operating system that came out last year. The update came a little over a week after Apple released macOS Tahoe 26.6.

In its security support document, Apple said that the update addressed a vulnerability that could allow an attacker to authenticate to Screen Sharing without valid credentials – in short, a bad actor could view a user's Mac screen and remotely take control of their keyboard and mouse. It appears however that hackers have already been taking advantage of the flaw.

As first reported by ArsTechnica, the NCSC-NL said that it had been notified of abuse of the vulnerability, "observed on multiple systems on which port 5900 was accessible from the internet." The reason is that when screen sharing is enabled, macOS's firewall intentionally exposes this port.

"In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed," the NCSC-NL added. In other words, a targeted Mac's resources are used to mine cryptocurrency.

When pushing the fix – which was also included in macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9 – Apple said it had addressed the authentication issue with "improved state management." Users who have not updated their Macs should do so as soon as possible. Even for those who have updated, use of a VPN is also recommended when screen sharing is active.

If you're not sure if your macOS version is up-to-date, you can check by going into your Mac's System Settings and selecting General ➝ Software Update.

Popular Stories

apple surprise and shine event

Apple Event Today: iPhone 18 Pro and iPhone Duo Cheat Sheet

Tuesday September 8, 2026 10:24 am PDT by
Apple's biggest event of the year is almost here, and all eyes are on Cupertino. With the first foldable iPhone expected to headline Apple's "Surprise and Shine" event on Wednesday, September 9, at 10:00 a.m. Pacific Time, the rumor mill has been running full throttle, fuelled by the biggest single design change in the life of the iPhone. To get you up to speed, here's a quick reference...
All Screen iPhone 2030 Feature Sans Text

iPhone 18 Pro: Nine Reasons Not to Upgrade This Year

Monday September 7, 2026 5:01 am PDT by
Apple is set to unveil new iPhone 18 Pro and iPhone 18 Pro Max models on Wednesday, September 9, and the devices are expected to feature a design that's largely similar to the iPhone 17 Pro models, with a peppering of enhancements inside. Major changes are not expected until next year, when Apple is expected to introduce a radically redesigned 20th-anniversary iPhone. If you're thinking of...
Surprise and Shine Live Coverage Article

Apple Event Live Blog: iPhone Duo, iPhone 18 Pro, and More Expected

Wednesday September 9, 2026 9:10 am PDT by
Apple's "Surprise and Shine" event kicks off today at 10:00 a.m. Pacific Time, where we're expecting to see the foldable iPhone Duo, the iPhone 18 Pro and Pro Max, Apple Watch Series 12 and Ultra 4 models, new AirPods 5 earphones, and perhaps some other announcements. Apple is providing a live video stream on its website, on YouTube, and in the company's TV app across various platforms. We...

Top Rated Comments

jchap Avatar
3 weeks ago

personal alternative: never installing Tahoe to begin with
The fix was also required and issued for Sonoma and Sequoia; it is not particular to Tahoe.
Score: 32 Votes (Like | Disagree)
chucker23n1 Avatar
3 weeks ago

Does the vulnerability persist if Screen Sharing is Off?
No.


Note that Apple generally leaves every possible "daemon" or "service" running regardless of whether it is being used / turned off.
It's the opposite: they generally design their daemons such that they only run when a socket is open. That's also true of screensharingd. You can easily try this yourself:

[LIST=1]
* With Screen Sharing disabled, open Activity Monitor, and search for screensharingd. You probably won't find it.
* Now in Terminal, do telnet localhost 5900. This will fail with "connection refused", as there's nothing listening. screensharingd still won't be running, of course.
* Now turn it on. Notice that screensharingd still isn't running!
* Finally, try telnet localhost 5900 again. This time, it'll work, and the very act of connecting to that port is what actually launches the daemon.

This is a mechanism in launchd with security and energy benefits. Instead of having screensharingd constantly listening for connections, launchd does the listening:

<key>Sockets</key>
<dict>
<key>Listener</key>
<dict>
<key>Bonjour</key>
<string>rfb</string>
<key>SockServiceName</key>
<string>vnc-server</string>
</dict>
</dict>




1) Enable Firewall (which for some reason defaults to off despite all the kabuki theater of Apple security)
I don't think that would do anything useful in this scenario. If you don't want Screen Sharing to accept connections, just leave it off. If you do, you'll also need to let the firewall allow it in.


3) Ensure everything in Sharing is off as well as all options under them (belts and suspenders people belts and suspenders)
Sure, but that's the default anyway.
Score: 13 Votes (Like | Disagree)
3 weeks ago
Of note: the default setting for Screen Sharing is OFF on macOS. So, unless you've specifically switched it on AFAIK you're not vulnerable to this particular exploit.
Score: 8 Votes (Like | Disagree)
3 weeks ago

How vulnerable is a computer behind a cable modem, etc. with a local IP address (10.0.*.*, 192.168.*.*)?
I would like to know that too. Most internet routers should block incoming connections from the Internet by default. Unless you explicitly forward all (or selected) ports to your Mac of course. But the article above is very not clear about that.
Score: 7 Votes (Like | Disagree)
Steve Adams Avatar
3 weeks ago

Which are?
Linux and Windows.....
Score: 6 Votes (Like | Disagree)
3 weeks ago
As I suggested in the other thread Apple should backport this fix to 10.14 and later (if needed) since those OSes are in active use. If they’re not vulnerable Apple should communicate that. They now leave open a very serious security issue that’s easy to exploit and gives a bad actor instant root access. That’s very, very bad.
Score: 6 Votes (Like | Disagree)