CompaniesU.S. equities

Apple Patches Critical macOS Zero-Day CVE-2026-65400 Exploited to Install Mining Malware

Published: Updated: By 24TopNews Editorial Desk

Apple has released an emergency security update to fix CVE-2026-65400, a critical zero-day vulnerability in macOS with a CVSS score of 9.8 out of 10. The flaw, caused by insufficient state management in the authentication process, allows network-based attacks without a valid password when Screen Sharing is enabled. Attackers have exploited it to gain root access and install Monero mining trojans. Affected systems include macOS Sequoia, Sonoma and Tahoe, with patches available via Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1. Apple credited security researcher Alfredo Pesoli of Bynario.

Apple has released an emergency security update to address a high-severity zero-day vulnerability in macOS. The flaw, tracked as CVE-2026-65400, carries a Common Vulnerability Scoring System (CVSS) score of 9.8 out of 10, placing it in the critical severity range. Attackers can exploit the vulnerability to compromise Mac devices over the network without supplying a valid login password.

The Dutch National Cyber Security Centre (NCSC-NL) issued a severe security warning, noting that the defect stems from insufficient state management in the macOS authentication process. When the built-in Screen Sharing feature is enabled, attackers can exploit the flaw to bypass standard login interception mechanisms and gain unauthorised access. The vulnerability was first identified earlier this month, and a working proof-of-concept (PoC) exploit circulated publicly last week. Cybercriminals have since used the code to compromise multiple Mac systems via port 5900, the default port for Screen Sharing.

Attackers have leveraged the vulnerability to obtain root-level privileges on macOS and install Monero cryptocurrency mining trojans on infected devices. The affected operating systems include macOS Sequoia, Sonoma and Tahoe. Apple has pushed patches for all affected versions; users can remediate the issue by updating to Sequoia 15.7.9, Sonoma 14.8.9 and Tahoe 26.6.1.

In its official security advisory, Apple thanked security researcher Alfredo Pesoli, co-founder and chief executive of Bynario, a cybersecurity company that develops AI-based automated vulnerability identification technology.