Vulnerability giving attackers full control of Macs is under active exploitation
Summary
Dutch officials warn of a high-severity macOS vulnerability (CVE-2026-65400) under active exploitation that enables remote code execution via screen sharing. Apple patched Tahoe, Sequoia, and Sonoma, but risk remains if port 5900 is exposed to the Internet. Current exploits have used Monero mining; attackers could deploy credential-stealing or more harmful malware in future.