Newsroom

Apple Patches macOS Screen Sharing Flaw Used to Install Monero Miners

17 August, 2026   /   News   /  AI   /   Tags:  macos, sharing, screen, monero, macs

Apple Patches macOS Screen Sharing Flaw Used to Install Monero Miners

Dutch cyber officials confirm active attacks granting root access on internet-exposed Macs via CVE-2026-65400

Apple has released security updates addressing a high-severity vulnerability in macOS Screen Sharing after the Netherlands’ National Cyber Security Centre confirmed that attackers were actively exploiting the flaw to seize full control of vulnerable machines and install Monero cryptocurrency mining software.

The issue, tracked as CVE-2026-65400, stems from improper state management in the authentication process used by the built-in Screen Sharing feature. This allows a remote attacker to bypass credential checks entirely when the service is enabled and port 5900 is reachable from the internet. Once inside, attackers obtained root-level privileges on affected systems.

Active Exploitation Confirmed

The Dutch National Cyber Security Centre updated its advisory on August 12 to report that it had received notifications of real-world abuse. In every confirmed case, the attacker gained root access and deployed a Monero miner. The agency did not disclose the number of compromised systems or attribute the campaign to any specific group.

Screen Sharing relies on the VNC protocol and opens TCP port 5900 when activated. While the feature is disabled by default and most home routers block the port, systems configured to expose it—particularly bare-metal Macs hosted for remote workloads—become accessible to anyone on the public internet.

In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.
Netherlands National Cyber Security Centre

Technical Details and Severity Upgrade

Security researchers identified the flaw in the Secure Remote Password authentication mechanism. An attacker can manipulate the service so that an unauthenticated connection is treated as authenticated, granting privileged access before normal login checks occur. Because the bypass happens prior to credential validation, changing Screen Sharing passwords, disabling legacy VNC options, or removing authorized accounts does not mitigate the risk.

Apple initially described the vulnerability as one that “may” allow an attacker without credentials to access a Mac. The U.S. Cybersecurity and Infrastructure Security Agency first scored it 7.1 but later raised the CVSS rating to 9.8 critical after reassessing the attack as requiring no privileges or user interaction and capable of full system compromise. Details of the bug were presented at the recent Black Hat security conference.

Security firm Huntress reported that a search of internet-exposed assets identified tens of thousands of potentially vulnerable hosts. The firm emphasized that this figure represents systems that appeared reachable rather than confirmed infections, with particular concern for newly provisioned hosted Macs that may still be running unpatched software.

Patches and Immediate Recommendations

Apple issued out-of-band updates on August 6 that correct the state-management logic and enforce proper authentication. The fixes are available in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Systems running earlier builds of these releases remain exposed until updated.

Until patches can be applied, users and administrators are advised to disable Screen Sharing through System Settings under General and Sharing. Keeping the service switched off when not required eliminates the attack surface. For environments that need remote access, routing traffic through a VPN or secure tunnel rather than exposing port 5900 directly is recommended.

No evidence has emerged so far that the attackers used the access for anything beyond cryptojacking. The same root privileges could, however, support additional malicious activity such as credential theft or further malware deployment. Monitoring for unexpected CPU usage, elevated power consumption, or anomalous network traffic remains prudent while systems are brought up to date.

Associated cryptocurrencies
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.