macOS screen-sharing flaw CVE-2026-65400 exploited to plant crypto miners, Apple patches it
Dutch cybersecurity officials warned that attackers are actively exploiting a high-severity macOS vulnerability in the screen sharing feature, gaining root access on exposed systems and installing Monero crypto miners. Apple issued a patch last week for Tahoe, Sequoia, and Sonoma after the flaw, rated 7.1 of 10, was disclosed at the Black Hat security conference; the company credited security firm Bynario with the finding.
GoKawiil's interpretation of the reporting above, not reported fact.
The bug targeted machines with port 5900 open to the internet, so the exposure appears limited to systems with remote screen sharing improperly configured, but it shows how a state-management flaw can escalate to full root access without credentials. Apple's hedged wording that the flaw 'may' allow unauthorized access reflects a common industry practice of cautious disclosure rather than certainty about real-world impact.
- CVE-2026-65400 is a macOS screen-sharing vulnerability that let attackers gain root access and install Monero miners.
- Apple patched the flaw last week for macOS Tahoe, Sequoia, and Sonoma after disclosure at Black Hat.
- Dutch cybersecurity authorities confirmed active exploitation on systems with port 5900 exposed to the internet.
Source: stratechery.com, 2026-10-05
Published there as: “Apple and a Hacker's Future”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.