Apple has recently addressed a significant security flaw affecting the screen sharing feature in macOS versions Sonoma, Sequoia, and Tahoe. Initially, the company released updates—macOS Sonoma 14.8.9, macOS Sequoia 15.7.9, and macOS Tahoe 26.6.1—describing them as providing “important security fixes” and recommending all users to update. Subsequently, Apple detailed that the updates resolved an authentication issue that could allow an attacker on the network to access Screen Sharing without valid credentials, achieved through improved state management.
Screen sharing vulnerabilities are particularly concerning because they can grant unauthorized users the ability to view the screen, open applications, access files, and perform actions as if they had physical access to the device. Initially, there was no evidence suggesting that this vulnerability was being exploited in the wild. However, recent reports indicate active exploitation. The Netherlands National Cyber Security Centrum has observed multiple systems with port 5900 accessible from the Internet being compromised. In these instances, attackers gained root access and deployed Monero cryptocurrency miners on the affected systems.
The active exploitation of this vulnerability raises significant concerns about potential unauthorized access to sensitive information, credential theft, and further system compromises. Users running the affected macOS versions are strongly advised to update their systems immediately to mitigate these risks.
To enhance security, it is recommended to enable screen sharing only when necessary and disable it immediately after use. Users can manage this setting by navigating to System Settings > General > Sharing and toggling the Screen Sharing option accordingly.
This incident underscores the critical importance of timely software updates and vigilant management of system settings to protect against emerging threats. As cyber attackers continue to exploit vulnerabilities, maintaining up-to-date systems and adhering to best security practices are essential steps in safeguarding personal and organizational data.