lidstah's lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
return2ozma@lemmy.world to Technology@lemmy.worldEnglish · 12 days ago

Vulnerability giving attackers full control of Macs is under active exploitation

arstechnica.com

external-link
message-square
9
link
fedilink
137
external-link

Vulnerability giving attackers full control of Macs is under active exploitation

arstechnica.com

return2ozma@lemmy.world to Technology@lemmy.worldEnglish · 12 days ago
message-square
9
link
fedilink
Screen-sharing bug lets remote hackers log in without a password.
alert-triangle
You must log in or register to comment.
  • Em Adespoton@lemmy.ca
    link
    fedilink
    English
    arrow-up
    39
    ·
    12 days ago

    How are people running their Macs exposed directly to the Internet?

    In order to make this work, a user would have to:

    1. Turn on screen sharing
    2. Turn off the OS firewall block
    3. Set up NAT routing on their router to forward port 5900 to their Mac

    Seems to me that anyone who could do this would know it was a really bad idea?

    Especially since you can already tunnel screen sharing via Apple ID or FaceTime to connect without leaving the port open.

    • muusemuuse@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      12
      ·
      12 days ago

      Synology support has told me to do equally dumb shit back when I still had synology products.

  • friend_of_satan@lemmy.world
    link
    fedilink
    English
    arrow-up
    25
    ·
    12 days ago

    The vulnerability, tracked as CVE-2026-65400, received a patch from Apple last week for macOS Tahoe, Sequoia, and Sonoma.

  • ag10n@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    12 days ago

    Apparently requires VNC to be open to the internet

    • muusemuuse@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      12 days ago

      Honest question: who still uses VNC? I think it’s only relevant because it’s just kind of a safe fallback but not because it’s particularly great at anything.

      • ag10n@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 days ago

        It’s built into every Mac

        https://support.apple.com/en-us/103229#%3A~%3Atext=Sharing%2C+Printer+Discovery-%2C5900%2C-TCP

        • muusemuuse@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          11 days ago

          I know, but I’ve never seen anyone use it. People use rustdesk or something like that anymore.

          • ag10n@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            11 days ago

            I use it for a headless Mac mini, otherwise yeah better solutions exist

  • PushButton@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    11 days ago

    It reads like: after someone deliberately configured their mac to expose a feature on the internet, someone “may” use it.

    It’s probably one of those “security issue found by AI”.

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 348 users / day
  • 3.55K users / week
  • 6.65K users / month
  • 12K users / 6 months
  • 1 local subscriber
  • 87.6K subscribers
  • 2.04K Posts
  • 16K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.worldB
  • BE: 0.19.20
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org