I keep a Mac mini at home doing jobs I’d rather not rent a server for, and Screen Sharing is exactly the kind of thing you flip on once, use twice, and forget forever. That’s the whole attack: the bug needs Screen Sharing explicitly enabled and the machine reachable from the internet, usually because someone forwarded a port. Nobody forwards 5900 on purpose after week one. It just survives.
So: kill the forward, put remote access behind a tunnel instead of a hole in the router, then patch to 14.8.9, 15.7.9, or 26.6.1. And note the timeline, because that’s what should change your habits — a security firm built a working exploit from Apple’s own patch in four hours, and single-fix patches are easy to reverse-engineer with modern AI systems. Patch day is the start of the race now, not the end.
The story — The Dutch NCSC observed active exploitation of a recently patched macOS Screen Sharing flaw letting remote attackers take over Macs with admin rights without credentials, on systems exposing port 5900. Attackers gained root and installed a Monero miner. Germany’s BSI and CERT Bund also warn, rating it “high.” Apple shipped an out-of-band fix. (Source)