Skip to content
Tech News
← Back to articles

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

read original more articles
Why This Matters

The exploitation of a macOS Screen Sharing vulnerability highlights the ongoing risks of remote desktop features being targeted by hackers, especially when exposed to the internet. This incident underscores the importance of timely software updates and security best practices to protect sensitive data and prevent malicious activities such as unauthorized access and cryptocurrency mining. For consumers and the industry, it serves as a reminder to remain vigilant and proactive in securing remote access tools.

Key Takeaways

The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.

The security issue lies in macOS Screen Sharing, a built-in remote desktop feature that allows remote desktop control over a network, using the VNC protocol over TCP port 5900.

Apple fixed CVE-2026-65400 on August 6 in macOS Tahoe 26.6.1 and earlier releases. The flaw allows network-based attackers to gain access without valid credentials.

An attacker could use this access to open applications remotely, access files, change security settings, and perform various other actions.

In an update to the initial advisory, the Dutch agency said it received a report indicating that the vulnerability is being exploited in the wild in attacks where port 5900 is exposed to the internet.

According to the NCSC, the attacker obtained root access to the system and deployed a Monero cryptocurrency miner.

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” reads the Dutch agency's update.

“In all these cases, root had been accessed on the affected system, and a Monero crypto miner had been placed.”

macOS users are recommended to upgrade their system to one of the following releases, which address CVE-2026-65400:

macOS Tahoe 26.6.1

... continue reading