Mac Vulnerability Exploitation and Apple’s Tightening Grip on AI Agents

3 min read
Source: Stratechery by Ben Thompson
Mac Vulnerability Exploitation and Apple’s Tightening Grip on AI Agents
Photo: Stratechery by Ben Thompson
TL;DR

A high-severity macOS vulnerability, CVE-2026-65400, is under active exploitation, allowing attackers to gain root access via exposed screen-sharing ports. While Apple patched the flaw, the incident highlights friction between AI agents and macOS security controls. Ben Thompson argues that Apple’s restrictive permissions and delayed smart-home strategy clash with the emerging reality of autonomous agents, which may render traditional app-based ecosystems obsolete.

Key points

  • CVE-2026-65400, a 7.1-severity flaw in macOS screen sharing, is being actively exploited to install Monero miners on systems with port 5900 open to the internet.
  • Apple released a patch for macOS Tahoe, Sequoia, and Sonoma last week, crediting security firm Bynario for the discovery, though the vulnerability details emerged at Black Hat.
  • Thompson’s own Mac Mini was compromised, but an AI agent (Claude) detected the breach, halted commands, and assisted in remediation before human intervention.
  • Apple recently issued a warning about 'Full Disk Access' for backup apps, citing risks from AI agents, and plans to require explicit user action for such permissions.
  • Thompson criticizes macOS’s Transparency, Consent, and Control (TCC) system for being incompatible with headless, agent-driven machines, as GUI prompts are invisible to background processes.
  • Apple is set to launch a smart-home hub, code-named J490, on October 13, featuring a 6-inch display and new Siri AI capabilities, alongside a HomePod mini update.

Background

Apple’s recent product cycles have focused on expanding its ecosystem, including the September 9 launch of the iPhone 18 lineup and potential foldable devices. The company has also increased prices for services like Apple TV+ and Apple One. These moves occur as Apple transitions under CEO John Ternus, with a renewed focus on AI integration through Siri and smart-home devices, following years of delays in AI development.

Why it matters

The incident underscores a growing tension between traditional security models and the rise of autonomous AI agents. As users delegate more tasks to agents, rigid permission systems may hinder functionality or create security gaps. Apple’s upcoming smart-home launch and stricter access controls signal a shift toward tighter user oversight, but may alienate power users who prefer open, agent-driven workflows. This could influence how consumers and developers approach device ecosystems in an era where AI can bypass traditional app interfaces.

What to watch

Apple is expected to announce its smart-home hub and updated HomePod mini on October 13, showcasing its new Siri AI. Users should ensure their macOS systems are updated to the latest point release to patch CVE-2026-65400. Apple may implement stricter controls for Full Disk Access, requiring explicit user consent for apps and agents. The broader market will watch how Apple’s app-centric model competes with open, agent-driven ecosystems like Meta’s Muse, which may offer more flexible integrations.

Share this article
Apple and a Hacker’s Future  Stratechery by Ben Thompson

Want the full story? Read the original reporting

Read on Stratechery by Ben Thompson