VMTech
Discuss a project

Apple Screen Sharing flaw abused to install Monero miners on Macs

Apple Screen Sharing flaw abused to install Monero miners on Macs

Apple’s critical macOS Screen Sharing vulnerability, CVE-2026-65400, is being actively exploited to install Monero cryptocurrency miners on internet-exposed Macs, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The authentication flaw has a CVSS score of 9.8 and affects the built-in remote desktop feature.

Apple addressed the issue in emergency updates released earlier this month: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. In its August 6, 2026 advisory, Apple said improved state management was used to ensure correct credential validation and block unauthorised authentication attempts. The company credited Alfredo Pesoli of Bynario with reporting the vulnerability.

Internet-exposed Screen Sharing hosts targeted

The NCSC-NL said it received reports of active abuse across multiple systems where port 5900 was accessible from the internet. In each reported case, an attacker obtained root access to the affected Mac and deployed a Monero miner.

The agency did not disclose when the activity was observed, how many devices were affected, whether exploitation began before patches were issued, or whether the campaign has objectives beyond cryptomining. The incident nevertheless links an exposed remote-access service to a direct compromise outcome.

The risk adds to the macOS threat activity outlined in macOS LotL attacks and SIM farms, where attackers also used native operating-system capabilities in wider intrusion chains. For organisations, the key distinction is that Screen Sharing exposure can create a reachable entry point rather than merely increasing local attack surface.

Logic flaws in the Screen Sharing server

CVE-2026-65400 is an authentication issue in Screen Sharing that can allow an attacker already on the network to authenticate to the service without valid credentials. Calif said the flaw is separate from a pre-authentication issue highlighted by researcher @osxreverser and fixed in macOS 26.6 alongside other Screen Sharing Server bugs.

Those related fixes included CVE-2026-43779, scored 9.8, involving network connections intended for another process; CVE-2026-43777, scored 7.5, which could permit remote denial of service; and CVE-2026-43760, scored 8.6, involving access to user-sensitive data.

Pesoli described CVE-2026-43760 as a post-authentication issue in a legacy VNC password path. Under specific configuration conditions, a viewer with the VNC password could turn file-copy operations into protected-file disclosure, arbitrary root file creation and remote root command execution.

Calif said the two pre-authentication flaws are logic bugs in the same source file. One stems from a stale return value after an oversized frame, while the other involves state-machine desynchronisation. Calif is withholding further technical detail on CVE-2026-65400 while more users install fixes.

Patch and reduce remote exposure

Businesses should update affected Macs to the current supported releases and identify devices with Screen Sharing or Remote Management enabled. Where immediate patching cannot be completed, Apple users can disable Screen Sharing through General, Sharing and the Screen Sharing toggle.

Teams should also review whether port 5900 is reachable from the public internet and restrict remote-access services to necessary, controlled network paths. The practical implication is clear: patching the listed macOS versions and removing unnecessary Screen Sharing exposure reduces the opportunity for attackers to turn a remote desktop service into root-level cryptomining access.

#macossecurity#vulnerability#cryptomining#endpointsecurity
Open analytics
On the site 0 views
min read 4 17.08.2026
Instagram

Apple Screen Sharing flaw abused to install Monero miners on Macs

Open the post on Instagram ↗