An AI Agent Built a Working Exploit for This macOS Flaw in Four Hours
Skip to content
Toggle Navigation
- News
- Events
- TNW Conference
- All Events
- Newsletters
- Advertise with us
- Jobs
- Contact
News
News
Latest
Deep tech
Sustainability
Ecosystems
Data and security
Fintech and ecommerce
Future of work
More
- Startups and technology
- Investors and funding
- Government and policy
- Corporates and innovation
Data and security
An AI agent built working exploits for this macOS flaw in four hours. Attackers are exploiting the macOS Screen Sharing flaw to gain root access and install Monero miners, according to the Dutch cyber agency. A security firm built working exploits for it using an AI agent in just four hours. Apple has since patched it, but two national agencies disagree on the severity of the issue.
August 17, 2026 – 10:41 pm
Credit: Canva
A security company built working exploits for two pre-authentication root bugs in macOS, achieving this in just four hours. The firm, Calif, used an AI agent. They are withholding technical details of one bug (CVE-2026-65400) until most Macs carry the patch due to how easily the exploit was created.
Attackers are using this bug actively.
What is happening to unpatched Macs?
The Dutch national cyber security centre revised its advisory on August 12th, reporting active abuse. All affected systems had port 5900 accessible from the internet.
“In all these cases, root access was obtained on the affected system and a Monero crypto miner had been installed,” the agency stated.
Every confirmed case involved root access followed by a miner installation.
The macOS Screen Sharing flaw allows an attacker on the network to authenticate to the remote desktop service without valid credentials. Apple refers to it as an "authentication issue" and claims improved state management addresses it. Screen sharing, the built-in feature that lets someone else watch your screen and control your keyboard and mouse, enables this by opening port 5900 in the macOS firewall when enabled.
Monero is the preferred coin for this type of attack due to two reasons: its transactions obscure sender, recipient, and amount; and its mining is suitable for ordinary CPUs, making a hijacked laptop valuable. TechRadar expects the attackers used XMRig, the most common Monero miner, though no confirmation exists.
The four-hour exploit time is what matters.
Cryptomining is the most visible damage, but it’s not the only concern. As Ars Technica pointed out, an attacker with root access could install something that steals credentials instead. The faster a patch becomes an exploit, the more concerning the situation becomes. This trend has been emerging since July when Microsoft credited AI with discovering a record number of vulnerabilities, followed by real-world exploitation in WordPress, Zoom, and its annotations.
Two agencies disagree on severity:
- Dutch Agency: Scores CVE-2026-65400 as 7.1 under CVSS version 3 (high but not critical).
- Ars Technica: Agrees with the Dutch agency’s rating.
- CISA: Rated it at 9.8, considered critical through its enrichment program that feeds the National Vulnerability Database. Many outlets, including The Hacker News, reported this higher score.
- NIST: Has not assessed it yet.
So, two national agencies disagree by 2.7 points on one bug. The body responsible for settling such disputes has yet to make a decision, and the agency scoring it lower is the one that discovered it being actively exploited.