Calif, a security research firm, announced that an AI‑driven agent produced functional exploits for two pre‑authentication remote‑root vulnerabilities in macOS in just four hours. The faster of the two, identified as CVE‑2026‑65400, is already being leveraged by threat actors to install Monero cryptocurrency miners on vulnerable systems.
Apple disclosed the flaw on August 6, crediting researcher Alfredo Pesoli of Bynario for the original discovery. The company shipped fixes in macOS 26.6.1, macOS 15.7.9 and macOS 14.8.9. The advisory warned that the built‑in Screen Sharing service, which opens TCP port 5900 when enabled, could be abused to gain root without valid credentials.
AI‑generated exploit and rapid weaponization
Calif’s AI agent reverse‑engineered Apple’s out‑of‑band update—a signal that the issue was critical—and then generated working code for both bugs in under four hours. The firm chose to withhold technical details on CVE‑2026‑65400 until most Macs receive the patch, citing the ease with which the exploit was created.
Meanwhile, the Dutch National Cyber Security Centre (NCSC) revised its advisory on August 12 after receiving reports of active abuse. The agency said every confirmed incident involved an attacker gaining root access and deploying a Monero miner. The malware, likely XMRig, runs on ordinary CPUs, making even a hijacked laptop profitable.
Scope of exposure
Security researcher “osxreverser” scanned the internet for hosts with port 5900 open and found roughly 40,000 reachable macOS machines, nearly half of them in the United States. Most were residential IPs, but the list also included university and corporate systems. A separate, more serious pre‑auth bug in the screen‑sharing daemon was fixed in macOS 26.6, but the researcher who discovered it did not report it to Apple.
Scoring agencies disagree on the severity. The Dutch NCSC assigned a CVSS v3 score of 7.1, while the U.S. Cybersecurity and Infrastructure Security Agency (CISA) rated it 9.8, labeling it critical. NIST has not yet published an assessment.
Apple’s response was swift: the advisory detailed the vulnerability, and the patch was made available within days of the public proof‑of‑concept presentation at Black Hat. The company recommends users install the update immediately. For those unable to patch, disabling Screen Sharing in System Settings → General → Sharing and blocking port 5900 at the router or firewall are interim mitigations.
Beyond cryptomining, the exploit grants attackers unrestricted root access, opening the door to credential theft, data exfiltration, or the deployment of additional malicious tools. Security experts warn that while many users lack the expertise to configure VPNs or SSH tunnels for safe remote access, leaving the service exposed poses a substantial risk.
The episode underscores a growing trend: AI‑assisted vulnerability discovery accelerating from research to real‑world exploitation. Earlier this year, Microsoft and WordPress reported similar AI‑driven findings, and a startup recently raised $60 million on the premise that patching can no longer keep pace with automated exploit generation.
For now, the most effective defense remains simple: apply Apple’s patch, turn off Screen Sharing when not in use, and ensure firewalls block inbound traffic on port 5900. As AI continues to lower the barrier to weaponizing software flaws, rapid patch deployment will become ever more critical.
Cet article a été rédigé avec l'assistance de l'IA.
News Factory APP - actualités agentiques pour booster votre SEO et AEO.