Claude Code agent catches macOS CVE-2026-65400 hack on a Mac Mini

Claude Code agent catches macOS CVE-2026-65400 hack on a Mac Mini

The author of the post says his computer was hacked, that it was his own fault, and that the way it happened is the interesting part. The machine was an always-on, headless Mac Mini that runs nothing but Claude and Codex. The hole was CVE-2026-65400, a bug in macOS screen sharing, which the post describes by quoting Ars Technica.\n\nThe vulnerability has a severity rating of 7.1 out of 10 and stems from a flaw in "state management" in the screen-sharing capability. Apple patched it the previous week for macOS Tahoe, Sequoia and Sonoma, and credited the security firm Bynario with reporting it. Details became public at the previous week's Black Hat conference. Apple said the bug "may" allow an attacker without credentials to gain access to a Mac; Ars notes it is unclear why Apple hedged. The Netherlands National Cyber Security Centrum (NCSC) warned that active abuse had been seen on multiple systems where port 5900 was reachable from the Internet. In its words: "In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed." Ars adds that when screen sharing is turned on, the macOS firewall opens that port.\n\nHow the author found out: his Claude Code thread runs a persistent monitoring tool that acts as an inbox for a status board and a Telegram bot. The tool stands down every 30 minutes, so the agent restarts it on a schedule, and that restart triggered an URGENT notification from Claude. Claude had more diagnostic information, unilaterally stopped executing all commands, and noted that the author's account could now run admin commands without a password, which it assumed was how the files were written. It suggested next steps, including that he stop invoking Claude. He ignored that one. He used Claude to root out the malware (they found the exact four second period in which the attacker gained access), build a tool to watch for a repeat, and then wiped the Mac Mini. All of this happened before he saw the Ars article. The Mac Mini has nothing on it except Codex and Claude, but he says you could make the case that he would have been in much more trouble without a persistently running agent. He also describes his separate agent Gecko, built for the people who work with him and deliberately limited in capability and access.\n\nThe second half is a complaint about Apple. Last week Apple's developer site published a note, Updates to Full Disk Access in macOS. It says Full Disk Access largely sidesteps privacy controls so backup apps can work, that some developers use it in ways that could put users at risk, and that Apple will introduce additional controls so this level of access can only be granted by "very explicit user action". It adds: "As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially." The author says he is massively nervous about what Apple's solution will entail.\n\nHe credits the Mac for scriptability, automation and accessibility APIs, for being a certified Unix system and for its hardware. But for a headless, always-on box he reaches from other computers and his phone through the ChatGPT and Claude apps, he calls macOS incredibly hostile. The main culprit is TCC (Transparency, Consent, and Control), whose permission prompts are GUI-only and sit in a protected space that no program can see. Programs fail silently, agents do not know why, and he has to remember to log in over screen sharing and click OK. He accepts the reason: if software could reach the prompts, malware could dodge them. His complaint is that TCC works at the wrong level, since agents write new programs all the time (for example ones touching SMB shares), and what he wants is a permission layer for agents, not for each program they create. In his telling, TCC leaves him no choice but to keep screen sharing on, which indirectly led to the hack. He says he should have used a VPN (his security approach rests on Tailscale) or SSH tunneling, and that this is his mistake.\n\nHis second grievance is the wording of a setting. He had set all his computers to install security updates automatically, but says that setting does not apply to most security updates; CVE fixes almost always arrive in point releases, and the latest point release was the fix for this bug. He calls it an honest mistake, made by trusting Apple to call a security update a security update, and says Apple demands ever more trust. He speculates that the iMessage store will be encrypted soon, and says some users may want to give an agent access to their messages, or simply use a Mac as a personal computer rather than an Apple-managed device increasingly like an iPhone.\n\nThe post then turns to Bloomberg's Mark Gurman, who wrote that Apple plans its long-delayed push into the smart-home market on Oct. 13.

Key facts

  • CVE-2026-65400 is a macOS screen-sharing bug rated 7.1 out of 10; Apple patched it for Tahoe, Sequoia and Sonoma, and the Dutch NCSC reports active exploitation on systems with port 5900 reachable from the Internet.
  • In the NCSC's cases, root was accessed and a Monero crypto miner was placed.
  • The author's headless Mac Mini, running only Claude and Codex, was breached; a Claude Code agent raised an URGENT alert, stopped running commands, and helped find the four second window of the intrusion before the author wiped the machine.
  • The author blames TCC permission prompts, which no program can see, for forcing him to keep screen sharing on, and says the automatic security-update setting does not cover most security updates.
  • Apple's note on Full Disk Access promises additional controls and cites the growing risks as AI agents become more capable and autonomous.

Why it matters

A real, patched macOS flaw is being exploited in the wild, and the story shows an AI agent acting as the first line of detection on the compromised machine. It also ties the incident to a wider argument: Apple's own note on Full Disk Access names AI agents as a growing risk, and the author fears the coming restrictions will make the Mac harder to use as an agent host.

Who it affects

Anyone running macOS Tahoe, Sequoia or Sonoma with screen sharing on and port 5900 reachable from the Internet, according to the NCSC's account. It also touches people who run agents on headless or always-on Macs, and developers whose apps rely on Full Disk Access, which Apple says it will gate behind very explicit user action.

How to use it

The practical steps come from the Ars Technica text the author quotes. Install the security update from last week. Block screen sharing, turn it on only when a session needs it, and switch it off afterwards in System Settings > General > Sharing. Security practitioners advise keeping port 5900 closed and connecting over a VPN or SSH tunneling instead. The author also warns that the automatic-install setting for security updates does not cover most of them, so point releases need checking by hand. His own setup for catching problems: a persistent monitoring tool in a Claude Code thread, restarted on a schedule.

How solid is it

The vulnerability facts (CVE number, 7.1 rating, affected macOS versions, Bynario credit, NCSC warning) come from Ars Technica and the NCSC as quoted by the author. The account of the Mac Mini intrusion and of Claude's behaviour is the author's own. The claim that he would have been in more trouble without an agent is framed by him as an argument ("you could make the case"). The prediction that the iMessage store will be encrypted is explicit speculation. What Apple's extra Full Disk Access controls will be, and when they ship, is not stated in the source.

Risks and caveats

The author's machine held nothing but Codex and Claude, so this is not a test of what an agent would do on a loaded personal Mac. Claude itself advised him to stop invoking it, and he overrode that. The source does not say how many systems were compromised in total, who the attacker was, or whether his Mac Mini ran a miner. It also does not say that Apple's Full Disk Access note was a response to this vulnerability. The author concedes the exposure was his own doing: screen sharing left on, no VPN or SSH tunnel, and a late point-release install.

“As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially.”

— Apple, developer-site note "Updates to Full Disk Access in macOS"