Back to Blog

Critical macOS remote‑control vulnerability: patch now to stop hijacking

Critical macOS remote‑control vulnerability: patch now to stop hijacking
August 16, 2026|David Velarde RoblesDavid Velarde Robles

Why this critical macOS remote‑control vulnerability matters to your business

A critical vulnerability in macOS screen‑sharing (CVE‑2026‑65400) is being actively exploited. Hackers can gain full control of a Mac without a password, install a crypto‑miner, or use the machine as a foothold for further attacks. If your company relies on Mac laptops – for design work, accounting, or any other daily task – you need to act now. The fix is simple, but the window to protect your business is closing fast.

What the vulnerability means for your business today

If your company relies on Mac laptops, the risk is immediate. The Dutch National Cyber Security Centre (NCSC) confirmed that the flaw is being used in the wild, with several infected machines already spotted. While the current payload is a crypto‑miner, the same access could be used to steal credentials, install ransomware, or spy on confidential data.

  • Active exploitation – real attacks have been observed on systems that expose port 5900.
  • High severity – the vulnerability scores 7.1 out of 10 on the CVSS (Common Vulnerability Scoring System, a rating that shows how severe a flaw is) scale.
  • Immediate impact – a compromised Mac can drain electricity, slow down workstations, and become a launchpad for attacks on other devices in your network.

What the vulnerability does

macOS includes a built‑in screen‑sharing feature that lets a remote user view and control the desktop. The bug lies in the way the system manages the state of that session. When port 5900 (the default screen‑sharing port) is reachable from the Internet, an attacker can:

  1. Initiate a screen‑sharing session without any credentials.
  2. Take control of the keyboard and mouse as if they were sitting at the computer.
  3. Run arbitrary code – in the wild we have already seen Monero crypto‑miners installed.

Step‑by‑step remediation

1. Install the latest macOS update

Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week. The update fixes the screen‑sharing state‑management bug.

Open System Settings → General → Software Update and install the available update on every Mac in your organization. Set the update to install automatically to stay protected against future fixes.

2. Turn off screen‑sharing when you don’t need it

Screen‑sharing is useful for remote support, but it should be treated like any other remote‑access tool.

  1. Open System SettingsGeneralSharing.
  2. Locate Screen Sharing and toggle it off.
  3. When you need to share a screen, turn it on, complete the session, then turn it off again.

3. Block port 5900 at the network level

Even if screen‑sharing is disabled, a misconfiguration can leave the port open.

  • If you have a router or firewall, create a rule that denies inbound traffic on TCP 5900 from the Internet.
  • For small offices that rely on a basic router, most default configurations already block this port; just double‑check the admin interface.

4. Use a VPN or SSH tunnel for legitimate remote access

When you really need remote access, route it through a secure channel:

  • VPN – creates an encrypted tunnel from the remote device to your internal network, hiding the traffic from the public Internet.
  • SSH tunneling – a lightweight alternative that forwards the screen‑sharing port through an encrypted SSH connection.

Both methods keep the vulnerable port hidden from the outside world while still allowing authorized users to connect.

5. Verify the patch and monitor for suspicious activity

After updating, run a quick check:

  • Open Activity Monitor and look for unfamiliar processes consuming CPU (crypto‑miners often show high usage).
  • Review the Security & Privacy pane for any unknown configuration profiles.
  • Consider a short‑term scan with a reputable anti‑malware tool to ensure no remnants remain.

FAQ – practical steps for small business owners

Q: My employees use Macs only inside the office. Do I still need to worry about this bug?
A: Yes. Even internal devices can be compromised if an attacker first gains access to your network (e.g., via a phishing email). Keeping the vulnerability patched eliminates a powerful foothold.

Q: I can’t afford a VPN for every employee. Is there a simpler way?
A: If a VPN isn’t feasible, the safest approach is to disable screen‑sharing completely and rely on in‑person support or secure file‑sharing services. The risk of leaving the port open outweighs the convenience of occasional remote control.

Q: How can I be sure all Macs are updated?
A: Use Apple Business Manager or a mobile‑device‑management (MDM) solution (mobile‑device‑management (MDM) solution) to push the update automatically. If you don’t have an MDM, a quick manual check on each device is essential until you can automate the process.

Keep your Macs safe with IT Move NL

A security breach can halt operations, damage reputation, and cost far more than a routine maintenance visit. At IT Move NL we help small businesses keep their Macs secure. Our Security & Protection + Maintenance & Support service can audit your fleet, apply patches and harden remote‑access settings. If you’d like a quick security review, just get in touch.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch