Dutch cyber officials warned this week that a high-severity macOS vulnerability is under active exploitation, according to the Netherlands National Cyber Security Centrum (NCSC). The vulnerability, tracked as CVE-2026-65400, stems from a bug in macOS screen sharing that allows remote attackers to view screens and control keyboards and mice on compromised machines.

According to Ars Technica, “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.” The NCSC noted that active abuse occurred on multiple systems where port 5900 was accessible from the Internet.
Apple released patches for macOS Tahoe, Sequoia, and Sonoma last week. The vulnerability carries a severity rating of 7.1 out of 10. The underlying cause is a flaw in “state management,” which tracks system events, user interactions, and variables. Apple said CVE-2026-65400 “may” allow attackers without credentials to gain access to a Mac, using notably hedged language common among tech developers disclosing vulnerabilities. Security firm Bynario reported the vulnerability to Apple.
Details of the exploit became public at last week’s Black Hat security conference. A video demonstration of the exploit was made available at that event.
One technology writer affected by the vulnerability discovered it only after an AI agent running on his Mac detected unusual activity. The agent’s persistent monitoring tool flagged suspicious behavior when it detected the system had been compromised and admin commands could execute without passwords. The agent then helped identify the exact window of exploitation, assisted in creating detection tools, and supported the cleanup process—all before the writer found the published Ars Technica reporting on the vulnerability.
This incident highlights a tension in macOS security architecture. While the Mac has long been praised for its scriptability, automation, and accessibility APIs that make it suitable for AI agent deployment, Apple appears concerned about granting such tools broad system access. Last week, Apple’s developer site announced “Updates to Full Disk Access in macOS,” warning that some developers are using Full Disk Access “in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history—without users’ full knowledge and understanding.” Apple said it will introduce additional controls requiring explicit user action before granting this level of access, particularly as “AI agents become increasingly capable and autonomous.”
Key facts
- CVE-2026-65400 is a high-severity macOS vulnerability in screen sharing with a 7.1/10 severity rating
- Attackers exploited the flaw to gain root access and install Monero crypto miners on affected systems
- The vulnerability affects macOS Tahoe, Sequoia, and Sonoma and has been patched by Apple
- Port 5900 exposure to the Internet was required for exploitation
- Details became public at Black Hat security conference last week
- An AI agent detected the author’s infection and helped identify the compromise window and cleanup
