出典:Ars Technica原文を見る ↗
原文の著作権は出典元に帰属します。当サイトでは収録、翻訳、体裁調整のみを行います。
メディア:0件確認済み、1件は出典のみ
事実関係
据 Ars Technica 报道,macOS 的屏幕共享(Screen Sharing)功能存在一个安全漏洞,远程攻击者可利用该漏洞在无需密码的情况下登录,从而获得对受影响 Mac 的完全控制。该漏洞目前正处于被积极利用(active exploitation)的状态。
报道配图显示为一台 MacBook Pro 设备,但相关技术细节(如受影响的 macOS 版本范围、漏洞编号 CVE、触发条件及修复补丁状态)在原文摘要中未提供。
解説と影響
屏幕共享是 macOS 内置的远程桌面功能,通常依赖账户密码或访问控制列表来限制谁能连入。一旦该认证环节被绕过,攻击者就相当于拿到了目标机器的交互式桌面权限,危害等级等同于本地登录——可以读取文件、安装持久化后门、窃取凭据,甚至横向渗透同一网络中的其他设备。
「在野利用」这一状态尤其值得警惕:它意味着漏洞已从理论风险转变为真实攻击,通常出现在漏洞被公开披露前后、补丁尚未普及的窗口期。对企业和个人用户而言,屏幕共享若暴露在公网或弱边界网络内,风险会被显著放大。在官方修复与版本信息明朗之前,临时禁用屏幕共享、限制其仅在内网可达,是相对稳妥的缓解思路。
从工程角度看,这类「认证绕过」型漏洞往往源于对远程会话握手流程的边界条件处理不当,与近期 RustDesk 在 Wayland 上实现无人值守远程访问 所讨论的远程控制生态形成对照——远程访问工具的安全模型正成为攻击者与防御者共同关注的焦点。
不確実性と限界
参考資料
出典原文
Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the Netherlands National Cyber Security Centrum warned earlier this week. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”
Do you know if your screen sharing is on? The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma. The vulnerability, with a severity rating of 7.1 out of 10, stems from a bug in the macOS screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. A flaw in the “state management,” which keeps track of preceding events, user interactions, variables, and other system states, is the underlying cause.