Apple Mac Flaw Lets Hackers Turn Devices Into Monero Miners
A critical authentication bypass in Apple's macOS Screen Sharing feature has been actively exploited to install Monero mining software on internet-exposed Macs. Dutch cyber authorities confirmed the attacks, and Apple issued a patch on August 6.
A critical flaw in Apple's built-in Screen Sharing feature has been actively exploited by hackers to commandeer Macs and use them to mine Monero ($XMR), according to Dutch cybersecurity authorities.
What the Vulnerability Does
The flaw, tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10 and lets attackers execute code remotely without valid credentials. It targets screensharingd, the system daemon that powers macOS's built-in remote desktop feature. Crucially, CVE-2026-65400 is a pre-authentication flaw, meaning the bypass occurs before the daemon reaches any authentication controls. That makes conventional defences useless: rotating the VNC password, disabling legacy VNC password access, or removing approved Screen Sharing user accounts all have zero effect on this vulnerability.
Any Mac with Screen Sharing enabled and port 5900 open to the internet is at risk. When a Mac user turns Screen Sharing on, the built-in macOS firewall automatically opens that port. Most home routers and dedicated firewalls block port 5900 by default, but if a network has been configured to allow it through, intentionally or otherwise, the machine becomes reachable from anywhere on the internet. Security firm Huntress estimated tens of thousands of Macs were potentially exposed, many of them machines rented by the hour from hosting companies.
Attacks Confirmed, Patch Available
The Netherlands' National Cyber Security Centre (NCSC) confirmed the attacks are not theoretical. In an update to its advisory, the NCSC said it received a report indicating active abuse of the vulnerability across multiple systems on which port 5900 was accessible from the internet, and that in all confirmed cases root access had been obtained and a Monero crypto miner placed on the device. The agency has not disclosed the number of machines affected or further details on the attackers.
The choice of Monero is deliberate. Monero has been a long-standing target of cryptojacking, where mining software is run on hijacked computers, given the token's ability to be mined on ordinary hardware rather than specialised rigs and the private nature of its transactions. U.S. officials subsequently re-rated the flaw's severity: CISA initially scored the vulnerability 7.1 out of 10 on the day Apple shipped the fix, then replaced that rating with a 9.8, near the top of the 10-point scale.
Apple patched the vulnerability on August 6. The only fixes are updating to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9, or disabling Screen Sharing entirely. Users who have not yet applied the update should do so immediately. Security experts also advise disabling Screen Sharing when not in use, ensuring port 5900 is not exposed to the internet, and connecting via VPN or SSH tunnelling as safer alternatives.
Sources:
Bleeping Computer: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
SC World: macOS screen sharing vulnerability actively exploited for crypto mining
The Hacker News: Apple macOS Screen Sharing Flaw Exploited to Install Monero Miner
Latest News
Read More...
Author
Soumen DattaSoumen has been a crypto researcher since 2020 and holds a master’s in Physics. His writing and research has been published by publications such as CryptoSlate and DailyCoin, as well as BSCN. His areas of focus include Bitcoin, DeFi, and high-potential altcoins like Ethereum, Solana, XRP, and Chainlink. He combines analytical depth with journalistic clarity to deliver insights for both newcomers and seasoned crypto readers.













