Hackers Exploit macOS Screen Sharing Flaw To Install Monero Miners

18-Aug-2026 Crypto Adventure
Hackers Exploit macOS Screen Sharing Flaw To Install Monero Miners

Attackers are actively exploiting a high-severity authentication flaw in Apple’s macOS Screen Sharing service, gaining root access to internet-exposed Macs and installing Monero cryptocurrency miners.

The Netherlands’ National Cyber Security Centre has identified active exploitation on multiple systems with port 5900 exposed to the internet. Users running affected macOS versions should install Apple’s August security updates immediately and avoid exposing Screen Sharing directly to the public internet.

Attackers Bypass Screen Sharing Authentication

Tracked as CVE-2026-65400, the vulnerability affects the authentication process used by macOS Screen Sharing. Insufficient state management allowed a network attacker to authenticate without valid credentials, giving an unauthorized user access that should have been rejected.

The Dutch NCSC updated its advisory on August 12 after receiving reports of exploitation across multiple systems. Every affected Mac identified in those reports had port 5900 reachable from the internet, with attackers obtaining root access and deploying a Monero miner.

The agency also confirmed that public proof-of-concept code is available. CVE-2026-65400 carries a CVSS 3 score of 7.1, placing it in the high-severity category rather than the critical range.

Apple’s Screen Sharing configuration uses TCP port 5900 by default for standard connections, making publicly exposed systems a direct target when the vulnerable service is enabled.

Apple Patches Three macOS Versions

Apple patched the Screen Sharing authentication flaw on August 6 with macOS Tahoe 26.6.1. The same correction was released for macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

The fix strengthens state management during authentication so that Screen Sharing accepts only valid credentials. Macs that do not require remote screen access should have Screen Sharing disabled, while administrators using the service should prevent port 5900 from being directly reachable from the public internet.

Systems that were previously exposed should also be checked for unauthorized access and unexpected processes, particularly cryptocurrency-mining software running with elevated privileges.

macOS Crypto Malware Threats Expand

The exploitation adds another macOS-focused threat to a growing series of attacks involving cryptocurrency infrastructure. A separate campaign uncovered in July used macOS malware to steal Telegram sessions, wallet databases and system credentials before replacing legitimate Ledger and Trezor applications with malicious versions.

Apple devices have also been targeted through software distributed inside official application stores. The SparkKitty malware campaign accessed users’ photo libraries in search of wallet recovery phrases and other sensitive information.

Apple released fixes for CVE-2026-65400 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9 on August 6, while the Dutch NCSC continues to classify active exploitation of unpatched, internet-exposed systems as known.

The post Hackers Exploit macOS Screen Sharing Flaw To Install Monero Miners appeared first on Crypto Adventure.

Also read: City Holder Daily Combo and Daily Quiz 18 August 2026: Daily Bonus
WHAT'S YOUR OPINION?
Related News