Apple just patched a critical macOS flaw that let hackers break in without a password

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust .

A hot potato: While traditionally a massive problem for Windows machines, zero-day flaws can wreak havoc on macOS as well. A newly disclosed vulnerability is about as dangerous as it gets, which is why Cupertino quickly fixed the issue on three different releases of its Mac operating system.

The Netherlands' National Cyber Security Centre (NCSC-NL) recently published an alarming security advisory about the new macOS flaw. It describes a vulnerability tied to an improper authentication process in Apple's line of desktop operating systems, which can have dire consequences on Mac systems when they have the built-in Screen Sharing feature turned on.

The vulnerability is tracked as CVE-2026-65400 and was assigned a CVSS score of 9.8. The CVSS system has a maximum severity of 10, which means CVE-2026-65400 is a highly dangerous flaw that should be patched as soon as possible.

The NCSC-NL describes the flaw as insufficient state management during the authentication process. Attackers could exploit the bug to break into a Mac over the network, gaining access without providing any valid login credentials. Under normal conditions, this kind of unauthorized login attempt would not be accepted by the OS.

The CVE-2026-65400 vulnerability was first discovered earlier this month. A week ago, the NCSC-NL obtained evidence of a working proof-of-concept (PoC) spreading through the public internet.

The flaw affects macOS Sequoia, Sonoma, and Tahoe, and Apple closed it off in versions 15.7.9, 14.8.9, and 26.6.1, respectively. Unknown criminals have been exploiting the PoC to break into "multiple" Mac systems through port 5900, which is open when the Screen Sharing feature is set to on.

The cyber-criminals have allegedly abused CVE-2026-65400 to gain root access to macOS and install a Monero cryptomining trojan on vulnerable systems. Most likely, things could have turned much worse: working root access means "game over" for any native security protections, plus the ability to essentially implant any kind of malicious code on the compromised system.

Apple has released a fix for all affected macOS releases, with separate bulletins for Sequoia 15.7.9 , Sonoma 14.8.9 , and Tahoe 26.6.1 . In all three support docs, Cupertino acknowledges Alfredo Pesoli for discovering the flaw. Pesoli is co-founder and CEO of Bynario, a cybersecurity company built around automated, AI-assisted vulnerability identification. In a LinkedIn post, Pesoli said his company's "Atlas" solution can help customers find and validate bugs as dangerous as this one.

See more TechSpot in Google Add us as a preferred source and our reporting shows up first when you search.
Add TechSpot

Featured on TechSpot