Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation, report ars technica.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
The vulnerability received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The glitch allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.
The Verge “says the safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended.” Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing.
However, the article notes that, currently, there are no indications exploits are being used to install anything other than Monero miners, which surreptitiously harness a Mac’s resources to perform mathematical operations that generate the cryptocurrency for the attacker. A bigger risk is that attackers might exploit the vulnerability to install malware that steals credentials or performs other more nefarious activities, notes The Verge.
I hope you’ll help support Apple World Today by becoming a patron. Almost all our income is from Patreon support and sponsored posts. Patreon pricing ranges from $2 to $10 a month. Thanks in advance for your support.




