A compromise of an always-on Mac mini has become a case study in the tension between powerful AI agents and operating-system safeguards. Stratechery author Ben Thompson said an attacker gained root access to a machine used for Claude and Codex after exploiting a macOS screen-sharing vulnerability, while an agent running on the computer helped flag the intrusion and support the subsequent investigation.
The vulnerability, identified as CVE-2026-65400, affects macOS screen sharing and was patched by Apple for Tahoe, Sequoia and Sonoma. According to the account, Dutch cyber-security officials warned that the flaw was being actively abused on systems whose port 5900 was exposed to the internet. Affected computers observed by the authorities had been accessed as root and had Monero cryptocurrency-mining software installed. Apple credited security company Bynario with reporting the bug.
Thompson said his Mac mini was a deliberately narrow environment containing little beyond the two coding agents. A persistent Claude process raised an urgent alert after noticing diagnostic signs and stopped executing commands. Thompson then continued using the agent during the investigation, eventually identifying a four-second period in which access was gained, creating a monitoring tool and wiping the machine. This is one person's account, not a general demonstration that an AI agent can safely remediate compromised systems.
The episode coincided with Apple announcing plans for stronger controls around Full Disk Access. That macOS permission can expose files, mail, messages and browsing history, and Apple said increasingly autonomous AI software raises the consequences of granting it. The company plans to require more explicit user action before applications receive such broad access.
That creates a design problem for users who want agents to perform sustained work. Restricting access can limit the damage caused by malicious or malfunctioning software, but repeated approval prompts can also prevent automation that depends on reading files, invoking tools and monitoring events without constant supervision. Thompson's argument is that the Mac's long history of automation makes it attractive as an agent host, while Apple's protective instincts could narrow that usefulness if new controls are too rigid.
The security lesson is more immediate than the platform debate. Internet-exposed remote-control services create a high-value path into a computer, and a patched operating system is essential when exploitation has been observed. Dedicated machines and constrained data access can reduce the consequences of a breach, but they do not remove the need to isolate services, limit privileges and rebuild a system after root compromise.
AI monitoring may have helped surface this incident, yet the same level of computer access can magnify risk. Apple's forthcoming design will need to distinguish deliberate, informed authorization from blanket permission while giving users a practical way to revoke and audit what autonomous software can do.



