An AI agent developed a functional exploit for this macOS vulnerability in just four hours.
A security firm developed working exploits for two pre-authentication root vulnerabilities in macOS within a span of four hours. The company, Calif, utilized an AI agent and is currently withholding technical information regarding one of these vulnerabilities, CVE-2026-65400, until a majority of Macs have the patch installed. The rationale behind this decision is the speed at which the exploit was created, indicating that attackers are already exploiting this vulnerability.
Updates on unpatched Macs indicate ongoing issues. On August 12, the Dutch national cybersecurity center revised its advisory after receiving reports of active exploitation. Affected systems had port 5900 accessible from the internet. According to the agency, “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been deployed.” Every verified incident involved unauthorized root access followed by the installation of a miner.
The macOS Screen Sharing vulnerability allows an intruder on the network to authenticate to the remote desktop service without the proper credentials. Apple considers this an authentication problem and states that improved state management addresses it. Screen Sharing is a built-in feature that permits someone to view your screen and control your keyboard and mouse. Activating this feature opens port 5900 on the macOS firewall.
Monero serves as the default cryptocurrency for this type of attack due to two main reasons: its transactions conceal the sender, receiver, and amount, unlike Bitcoin, which records them on a public ledger, and its mining is compatible with standard CPUs, making a compromised laptop valuable. Although it’s speculated that attackers used XMRig, the most prevalent Monero miner, there has been no confirmation.
The exploit being created in four hours is the key factor. Cryptomining is the visible consequence, but it's arguably the least significant issue. Ars Technica pointed out a more alarming escalation: an attacker with root access could potentially install software to steal credentials. The rapid transition from patch to exploit highlights a pressing concern. Calif reverse-engineered Apple's out-of-band update, noting that such updates signify critical issues, as they are rare.
Using an AI agent, the firm managed to create working exploits for two distinct pre-auth remote root vulnerabilities in less than four hours. This trend continues, as reported in July when Microsoft credited AI for discovering a record number of vulnerabilities. Researchers have also observed AI-generated vulnerabilities leading to real-world exploitation, a pattern that emerged shortly after with platforms like WordPress and more recently Zoom. With a startup recently raising $60 million based on the belief that patching can't keep pace, Apple has become another target.
The situation is further complicated by differing evaluations of the vulnerability. The Dutch agency rates CVE-2026-65400 at 7.1 under CVSS version 3, indicating it as high but not critical, while CISA rates it at 9.8, categorizing it as critical through its enrichment program. This discrepancy has been echoed by various media outlets, despite NIST not having assessed it at all, leaving one of the national agencies at odds with another.
A researcher known as osxreverser scanned for accessible screen sharing hosts and identified approximately 40,000 that could be reached from the internet, nearly half of which were located in the United States. Most of these were associated with residential addresses, but the list also included university systems and corporate servers. He raised concerns about a more serious flaw involving a pre-authentication bug in the screen sharing daemon, which required only an IP address, a vulnerability fixed in macOS 26.6.
Apple issued its advisory on August 6, crediting Alfredo Pesoli from the security firm Bynario. Fixes were included in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Public details emerged during the Black Hat conference that same week. The Dutch agency first advised on August 7 and then revised its statement on August 12 after public proof of concept and reports of abuse surfaced. Pesoli had previously documented a related vulnerability that allowed a remote viewer to access protected files as root and create files under root privileges, which he exploited to formulate a sudoers policy and facilitate remote root command execution.
In terms of mitigation, users should install the update to resolve the issue. If immediate patching isn’t feasible, it is recommended to turn off screen sharing by navigating to System Settings, selecting General, and then Sharing to toggle it off, only enabling it during necessary sessions. Additionally, blocking port 5900 at the router or firewall is advisable as a fallback measure rather than a complete fix.
Experts have long suggested keeping port 5900 closed even during screen sharing use, utilizing VPN or SSH tunnel for remote connections instead, although these alternatives may not be practical for most users. Many questions remain unanswered, including when the attacks commenced, how many systems were affected, or whether the flaw was exploited prior to Apple releasing the patch. Current evidence suggests that no
Other articles
An AI agent developed a functional exploit for this macOS vulnerability in just four hours.
The vulnerability in macOS Screen Sharing is currently being exploited. An AI developed a functional exploit in just four hours. It's recommended to apply a patch or disable screen sharing.
