Critical Apple Screen Sharing Flaw Lets Hackers Hijack Macs to Mine Monero

By Giuseppe Ciccomascolo // August 17, 2026 @ 03:03 PM Make AlphaWire Logo preferred on Google News

Share

Critical Apple Screen Sharing Flaw Lets Hackers Hijack Macs to Mine Monero

Share

Point of Focus

  • CVE-2026-65400 lets attackers bypass macOS Screen Sharing authentication.
  • Confirmed attacks gave hackers root access to internet-exposed Macs.
  • Apple patched the critical flaw on August 6 across Tahoe, Sequoia and Sonoma.

 

Apple has patched a critical macOS Screen Sharing vulnerability that attackers exploited to take control of internet-exposed Macs and install Monero mining software.

The vulnerability, tracked as CVE-2026-65400, allows attackers to bypass authentication and access Screen Sharing without valid credentials. The Netherlands’ National Cyber Security Centre confirmed several incidents in which attackers obtained root-level access to affected Macs.

Apple released security updates on Aug.  6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. Macs that have not installed the relevant update remain at risk, particularly when Screen Sharing is accessible through the internet.

 

Flaw bypasses screen sharing authentication

Apple described CVE-2026-65400 as an authentication vulnerability caused by improper state management. The flaw affects the Secure Remote Password process used by macOS Screen Sharing.

Security researchers at Huntress found that an attacker could manipulate the service into treating an unauthenticated connection as authenticated. Successful exploitation could provide privileged remote access without requiring user interaction or existing account credentials.

 

 

Changing a Screen Sharing password, removing authorized accounts or disabling legacy VNC authentication does not address the underlying vulnerability. Users must install Apple’s security update or disable Screen Sharing until they can patch their systems.

CISA has assigned the flaw a critical CVSS score of 9.8, reflecting its low exploitation requirements and potentially severe impact.

 

Attackers installed Monero miners

The Dutch NCSC said compromised systems had port 5900, commonly associated with Screen Sharing, exposed to the internet. In the confirmed incidents, attackers gained root access and installed software that used the Macs’ resources to mine Monero.

Monero is frequently used in cryptojacking campaigns because it can be mined with general-purpose processors.

 

 

However, cryptocurrency mining may represent only one possible outcome of a successful attack.

Root-level access could also enable data theft, credential harvesting, persistent malware deployment and lateral movement into other connected systems. The NCSC has not attributed the attacks or disclosed the mining software, wallet addresses or proceeds associated with the campaign.

 

Thousands of Macs potentially exposed

Huntress reported finding tens of thousands of potentially vulnerable internet-facing hosts, although this does not mean every identified machine was compromised.

Hosted bare-metal Macs, including Mac minis rented for remote workloads, may face elevated risk because some providers expose Screen Sharing on newly provisioned systems.

Internally accessible Macs could also be vulnerable if an attacker first gains access to the local network.

Mac users should install the latest security update immediately. Those unable to update should disable Screen Sharing and Remote Management under the Sharing section of macOS System Settings, while administrators should also block unnecessary external access to port 5900.

Share

Default avatar

Giuseppe Ciccomascolo

After graduating with a Master’s in Advanced Journalism at the London School of Journalism Giuseppe worked as an analyst and Senior Reporter. In 2017, he transitioned to covering cryptocurrency-related news, producing documentaries and articles on Bitcoin and other emerging digital currencies and played a pivotal role in establishing the academy for a cryptocurrency exchange website.

Table of content

Ad

Related Articles