This is one outlet's own report from 9to5Mac — the article as it was filed. Other outlets are covering the same event; open the full story to compare every source side by side.
See the full story · 5 sourcesThis is one outlet's own report from 9to5Mac — the article as it was filed. Other outlets are covering the same event; open the full story to compare every source side by side.
See the full story · 5 sourcesGo to the 9to5Mac home page Switch site 9to5Toys 9to5Google Logo 9to5Google Electrek Drone DJ Logo DroneDJ Space Explored About Privacy Toggle social menu Toggle dark mode Search for: Submit Toggle search form Forums Store Podcasts Apple@Work Happy Hour 9to5Mac Daily Overtime iPhone iPhone Mac Mac MacBook Pro MacBook Air iMac Mac mini Mac Studio Mac Pro iPad iPad Pro iPad Air iPad mini iPad iPadOS Watch Apple Watch Apple Watch Ultra Apple Health Apple Watch SE Vision Vision Pro visionOS Music and TV Apple Music AirPods HomePod Apple TV Guides Reviews How Tos AAPL Apple Store Apple Arcade Apple Card Apple Silicon Apple One Apple Fitness+ CarPlay Siri HomeKit Toggle dark mode Mac Privacy Security A serious Mac screen sharing vulnerability is being actively exploited Ben Lovejoy | Aug 17 2026 - 4:36 am PT 1 Comment Apple recently released updates to three versions of macOS, stating that they fixed a serious screen sharing vulnerability in macOS Tahoe, Sequoia, and Sonoma.
At the time, there was no indication that the security flaw was being exploited in the wild, but now there is, so if you haven't yet updated your Mac , you'll want to do so asap …
Earlier this month, Apple released macOS Sonoma 14.8.9, macOS Sequoia 15.7.9, and macOS Tahoe 26.6.1, with the release notes initially stating only that they provided “important security fixes” and were recommended for all users. The company later expanded on this .
Impact: An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
Description: An authentication issue was addressed with improved state management.
Screen sharing is of course one of the most dangerous features for a security hole, since it potentially allows an attacker to view your screen, open apps and files, and do pretty much anything else they could do if they had physical possession of your logged-in machine.
At the time, Apple said there was no evidence of the vulnerability being exploited in the wild, but that is no longer the case, as Arstechnica reports.
"The Netherlands National Cyber Security Centrum has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the body warned […]
“In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
As the site notes, the fact that this is being actively exploited raises the prospect of attackers stealing credentials and more. If you are running any of these macOS versions and haven't yet updated, you should do so immediately.
It's also best practice to ensure that screen sharing is only enabled when you actively want to use the feature.
Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing.
It should be disabled immediately after your session ends.
FTC: We use income earning auto affiliate links. More.
Check out 9to5Mac on YouTube for more Apple news:
Expand Close comments Expand Close comments Guides Mac Apple’s Mac lineup consists of MacBook, MacBoo…
Privacy is a growing concern in today's world. F…
Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He's known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!
AIPROPX is an independent multi-source news index — we track, compare, and connect coverage from across the web into one place you won't find anywhere else.