Skip to content

Topic

macOS Security

Vulnerabilities, patches, and exploitation affecting Apple's macOS platform and its built-in services.

Current stories

invest4 publishers

Inc. columnist says Meta's Muse synced his texts to row 187,462 with Full Disk Access off

Inc. columnist Jason Aten says Meta's Muse agent synced his Mac texts up to row 187,462 while Full Disk Access showed as off. Meta says that cannot happen, so the dispute is over whether a settings screen shows users what an agent can actually read.

Perspective Coverage

5 publishers
Builder
Builder 34%
Operator
Operator 42%
Investor
Investor 24%

Reality

Evidence40
Adoption65
Hype gap+30
Incentives60
Confidence55
product5 publishers

Apple's quiet Screen Sharing fix is now a same-day job: CVE-2026-65400 is under active abuse

Dutch officials report root access and Monero miners on Macs with port 5900 open to the internet. Sonoma, Sequoia and Tahoe all need the update Apple shipped as an important security fix.

Perspective Coverage

5 publishers
Builder
Builder 22%
Operator
Operator 70%
Investor
Investor 8%

Reality

Evidence70
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence68
security6 publishers

macOS Screen Sharing bug exploited in the wild: if port 5900 was open, assume root was taken

The Dutch NCSC says CVE-2026-65400 was abused within two weeks of Apple's fix, with root access and Monero miners in every reported case. Patching closes the door; it does not evict anyone.

Perspective Coverage

6 publishers
Builder
Builder 22%
Operator
Operator 72%
Investor
Investor 6%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence62
build1 publisher

Binding a dev server to 0.0.0.0 hands it to everyone on the LAN

A developer scanned their own MacBook from a second machine on the same network. The parts macOS ships were invisible; the exposure that stayed open was the dev servers they had left running, wider than they thought.

Publishers:dev.to

Reality

Evidence50
Adoption
Insufficient
Hype gap+5
Incentives65
Confidence55
security3 publishers

JFrog says a stock Parallels Desktop install hands any local user a root shell

JFrog found that an unprivileged account on a Mac running Parallels Desktop 26.4.0 can reach the root dispatcher over a world-writable socket and run code as uid 0 through argument injection in the appliance installer.

Perspective Coverage

3 publishers
Builder
Builder 34%
Operator
Operator 48%
Investor
Investor 18%

Reality

Evidence80
Adoption42
Hype gap+10
Incentives55
Confidence76
security3 publishers

Any local process can rewrite the dictation endpoint in Meta's new Muse assistant

Patrick Wardle published working code that sends Muse's dictated audio to a server of the attacker's choosing. Because the assistant holds file, microphone, camera, calendar and paired-iPhone access, whoever redirects it inherits all of it.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 54%
Investor
Investor 13%

Reality

Evidence70
Adoption
Insufficient
Hype gap+20
Incentives45
Confidence65