Mac Can Be Hacked Without Password, Update Immediately
Mac users are being urged to update their device’s operating system immediately. Hackers are reportedly already exploiting a security flaw in Apple’s Screen Sharing feature to break into Macs without requiring a valid password.
The Dutch National Cyber Security Centre (NCSC) issued a warning after receiving reports of several incidents that exploited the vulnerability to install Monero cryptominers.
The security flaw is recorded as CVE-2026-65400 and was patched by Apple on 6 August 2026. The vulnerability is an authentication bypass flaw in the Screen Sharing feature in macOS that allows an attacker on the network to connect to a device without valid credentials, as reported by Malwarebytes on Wednesday (19/8/2026).
Screen Sharing is a built-in macOS feature that allows users to control a Mac remotely. The service generally runs over port 5900.
If the flaw is successfully exploited, an attacker can gain access to view and control the Mac remotely. In the cases discovered by the NCSC, hackers even managed to obtain root access and install software to mine Monero.
Apple fixed the flaw through a mechanism described as improved state management. This fix indicates a problem in the authentication process or session state validation, rather than a flaw in the cryptographic system.
Apple has released fixes for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
The highest risk threatens Macs that have Screen Sharing enabled and make port 5900 accessible from the internet. This can occur, for example, when a user performs port forwarding on a router, uses a public IP address, or runs the device through a hosting provider.
However, Macs that are only accessible from an internal network remain potential targets. In that scenario, a hacker must first gain access to the same network.
The cases discovered so far are indeed related to Monero mining. Hackers likely chose Monero because its mining process does not depend on highly specific ASIC devices. Mining can be done using either a CPU or GPU.
Nevertheless, cryptomining is not the only threat. If a hacker manages to obtain root-level access, they could potentially maintain access to the device, steal data, harvest credentials and security keys, install additional malware, and move laterally to other devices on the network.
How to Protect Your Mac
The main recommended step is to update macOS immediately. Users can open the Apple menu in the top-left corner of the screen, then select System Settings.
Next, select General, then Software Update. The Mac will check for available updates. If an update appears, select Update Now or Upgrade Now, then follow the on-screen instructions.
Users may need to enter an administrator password. Ensure the Mac remains connected to the internet and a power source until the update process is complete, as the device may restart.
If macOS cannot be updated yet, users can disable Screen Sharing if the feature is not in use.
To do this, open Apple Menu > System Settings > General > Sharing, then look for Screen Sharing. If the feature is active, turn off the toggle.
Users are also advised to check Remote Management on the same Sharing page. That feature provides another route for controlling the Mac remotely, so it should be disabled if it is not needed for work or IT support purposes.