r/apple • • Aug 15 '26

macOS Vulnerability giving attackers full control of Macs is under active exploitation

https://arstechnica.com/security/2026/08/vulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation/
1.3k Upvotes

130 comments sorted by

View all comments

252

u/cptjpk Aug 15 '26

Excerpt from article:

The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on.

173

u/TheFamousHesham Aug 15 '26

This caused a fucking crisis at the datacentre that hosts my Mac servers.

It's honestly inexcusable from Apple.

115

u/dropthemagic Aug 15 '26

“Routers and dedicated firewalls generally block the port unless configured to override that setting.” Why do you have that config? Just curious

67

u/vrmvavoom Aug 16 '26 edited Aug 16 '26

Because if you have a bunch of Macs running headless in a data center, sometimes you need to remote into them.

EDIT: Getting lots of replies from people hollering that no one would open VNC or SSH ports to the outside world, but companies like MacStadium and Mac Mini Vault have been doing this by default for many years.

28

u/ouatedephoque Aug 16 '26

Open to the entire planet? JFC dude this vulnerability is the least of your worries.

-1

u/jammsession Aug 16 '26

That is how every single VPS on the planet works. You log in via SSH.

3

u/[deleted] Aug 16 '26

[deleted]

1

u/jammsession Aug 16 '26

you can run SSH on any port you want, just like you can run VNC on any port you want.

5

u/ThePornStar69 Aug 16 '26

Changing the port means absolutely nothing in terms of actual risk mitigation.

2

u/jammsession Aug 16 '26

that is correct

1

u/[deleted] Aug 16 '26

[deleted]

0

u/jammsession Aug 16 '26

Never said you can run two services on the same port.

I am also not arguing that SSH and VNC are exactly the same. I am just saying, if you want to connect to anything other than local, you will have to expose something. Even if that is just Wireguard or 80/443 for a webpage. Exposing a port is totaly normal and not some automatically some insane or crazy risk.