Go Back

Mac Screen Sharing Flaw Hijacked for Monero Mining

Mac Screen Sharing Flaw Hijacked for Monero Mining

Murugaverl Mahasenan

Murugaverl Mahasenan

Make Catenaa preferred on (opens in a new tab)

Catenaa, Wednesday, August 19, 2026-Hackers have exploited a serious macOS Screen Sharing vulnerability to take control of internet-facing Macs and install Monero mining software, according to the Netherlands’ National Cyber Security Centre.

The flaw, tracked as CVE-2026-65400, affects Apple’s Screen Sharing service and allows an attacker to authenticate without valid credentials.

Apple patched the vulnerability Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

The Dutch NCSC later updated its advisory after receiving reports of active exploitation.

The agency said multiple affected systems had port 5900 exposed to the internet. Attackers obtained root access in each observed case and installed software designed to mine Monero, or XMR.

The NCSC did not identify the attackers or disclose how many Macs were compromised.

The vulnerability is especially dangerous because attackers do not need a legitimate Screen Sharing password.

Apple described CVE-2026-65400 as an authentication issue caused by improper state management.

Security researchers at Huntress said the weakness occurs before authentication is completed. That means changing passwords or removing authorized Screen Sharing accounts does not address the underlying flaw.

An attacker who can reach a vulnerable Screen Sharing service can potentially cause the Mac to treat the connection as authenticated.

Huntress said exploitation can allow attackers to read and write files with root-level privileges.

That gives an intruder far more control than an ordinary compromised user account.

Screen Sharing is disabled by default on standard Macs.

The risk is greater for systems deliberately exposed for remote access, including hosted Mac minis and other bare-metal Apple servers used for development, testing and cloud workloads.

Huntress researchers said searches of internet-exposed systems identified tens of thousands of potentially vulnerable hosts.

The vulnerability’s risk rating has also changed since Apple released its patch.

The U.S. National Vulnerability Database currently displays a 9.8 out of 10 critical CVSS score supplied through CISA’s vulnerability enrichment system.

The Dutch NCSC advisory continues to display a 7.1 high-severity score.

The difference reflects how rapidly the understanding of the flaw evolved after researchers examined its practical impact.

Public proof-of-concept code is now available, while the Dutch agency has confirmed real-world exploitation.

That combination raises the risk for Mac systems that remain unpatched and reachable from outside trusted networks.

The attacks also highlight Monero’s long-running connection with cryptojacking.

Cryptojacking involves secretly using someone else’s computing resources to mine cryptocurrency.

Instead of stealing crypto already stored on a machine, attackers convert its processing power into mining income.

Monero is attractive for this type of attack because its proof-of-work system is designed to support mining on general-purpose hardware rather than depending entirely on specialized mining equipment.

Its privacy architecture also hides transaction details such as senders, recipients and amounts by default.

That does not make Monero responsible for cryptojacking. The cryptocurrency’s mining design and privacy characteristics, however, have made it a recurring choice among attackers seeking to monetize compromised computers.

A single hijacked Mac is unlikely to generate large returns.

The economics change when attackers can compromise many machines and combine their computing power.

Catenaa View

The incident shows how cryptocurrency mining can become the final stage of an otherwise conventional cybersecurity breach.

The attackers did not need access to victims’ crypto wallets, private keys or exchange accounts.

They needed computing power.

Once root access was obtained, the Mac itself became the asset being stolen.

That distinction matters as crypto-related attacks continue to spread beyond exchanges, wallets and blockchain protocols.

Cryptojacking converts ordinary infrastructure into unauthorized mining equipment, often leaving victims to absorb higher electricity usage, reduced performance and possible hardware strain.

The latest case also exposes the risk created when remote-access systems are placed directly on the public internet.

A service designed to make remote administration easier can become an entry point if authentication controls fail.

What Users Should Do

Apple users running Screen Sharing should install the latest macOS security updates. Systems should be upgraded to Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9, depending on the installed operating system. Organizations that cannot update immediately should disable Screen Sharing or prevent the service from being directly reachable from the public internet.

Password changes alone are not considered a fix for CVE-2026-65400 because exploitation occurs before normal authentication.

Apple’s Screen Sharing service allows users to remotely view and control a Mac from another computer. The service uses technology related to the VNC remote-desktop protocol and commonly operates through port 5900. Apple does not enable Screen Sharing by default, but it is frequently used on remotely hosted Macs and development systems. CVE-2026-65400 was publicly disclosed in August after researchers identified weaknesses in the service’s authentication process. Apple issued patches on Aug. 6. The Dutch NCSC subsequently reported confirmed attacks involving root access and Monero mining software.