What Happened
Apple patched a critical authentication bypass in macOS Screen Sharing on August 6, tracked as CVE-2026-65400, and attackers began exploiting it within days of a public proof-of-concept exploit going live. The flaw sits in screensharingd, the daemon powering macOS’s built-in remote desktop feature, and lets a remote attacker bypass authentication entirely on Macs with port 5900 exposed to the internet. The Dutch National Cyber Security Centre confirmed active exploitation in advisory NCSC-2026-0280, reporting root access obtained and a Monero cryptocurrency miner installed on every confirmed victim system. CISA rescored the vulnerability from 7.1 to 9.8 on August 14 after reassessing the attack path as requiring no privileges and granting full compromise of confidentiality, integrity, and availability. Apple’s fixes ship in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, or organizations have the option to disable Screen Sharing entirely as an interim step.
Why This Matters for Canadian Organizations
Canadian government departments, universities, media production studios, and design firms run large Mac fleets, and any Mac left with Screen Sharing exposed directly to the internet now sits within reach of an unauthenticated root compromise. Cryptomining is the payload observed so far, but root access on a compromised endpoint gives an attacker the same footing needed for data theft or lateral movement into a connected network. Organizations subject to OSFI Guideline B-13 face expectations around timely patching of critical vulnerabilities, and a flaw rescored to 9.8 with confirmed in-the-wild exploitation clears this threshold directly. Under PIPEDA, confirmed unauthorized access to systems holding personal information triggers breach assessment obligations, regardless of what payload the attacker ultimately deployed.
What to Do
IT teams should inventory internet-facing Macs immediately, confirm none expose port 5900, and apply the August patches across managed device fleets without delay. Where Screen Sharing is not actively required for remote support, disable it outright rather than relying on network-level restrictions alone. Full technical detail is available from The Hacker News and SecurityWeek.






