Apple has released updates for macOS Tahoe, Sonoma, and Sequoia to address a Screen Sharing vulnerability that could let an attacker authenticate to Screen Sharing without valid credentials. The flaw can allow a remote party to view a Mac’s screen and potentially control the keyboard and mouse.

Initially, Apple’s fixes were issued without clear public evidence that the vulnerability was being exploited in the wild. However, multiple outlets report that the Netherlands’ National Cyber Security Centre (NCSC-NL) has observed real-world abuse. According to NCSC-NL, activity was seen on multiple systems reachable from the internet via port 5900, which macOS can expose when Screen Sharing is enabled. In those cases, attackers reportedly gained root access and installed a Monero cryptocurrency miner.

Apple says the updates address the authentication issue through “improved state management” and that the fix appears in multiple versions (including Tahoe 26.6.1, and also corresponding Sonoma and Sequoia patch releases). Outlets also recommend that users update and consider using a VPN while Screen Sharing is active.