The vuln required "port 5900 was accessible from the Internet"
Why would anyone open up random ports (or even all ports) to the internet?
The thing is that many of these people think they know what they are doing and do not think about security, only how awesome LLMs and AI make their experience until something bad happens.
Even though this was a valid critical bug [1], you need to enable screen sharing and allow connections to and from port 5900 on your router for a remote person to be able to exploit this.
Any security conscious person would probably be using a VPN (Wireguard or Tailscale) to prevent something like this, in the first place.
> almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.
The line above tells you how seriously this person takes security prompts.
I opened my SSH port to the internet back in the day because I could tunnel my internet through it to avoid network blocks. (sshuttle my beloved)
it's a vnc port, it'd also require the router to have it opened. Reading the article I think the user opened it themselves. It does get opened automagically on the mac side when screen sharing is turned on.
> The problem is that for my particular use case — a headless, always-on Mac Mini that I primarily access from other computers and my phone through the ChatGPT and Claude apps — macOS is incredibly hostile
> As noted by the NCSC, the vulnerability is being exploited when port 5900 is exposed to the Internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting.
> Obviously I should have — and will be — using a VPN going forward (the foundation of my entire approach to security is Tailscale); what I will note, however, is that TCC basically leaves me no choice but to have screen sharing enabled if I want to actually use my Mac Mini in the way I want to use it. I use screen-sharing constantly — including from my phone — and almost every time it’s to click “OK” on a stupid prompt that I’ve long since stopped taking seriously.