Hackers Exploit macOS Screen Sharing Flaw for Monero Mining

Photo: BleepingComputer
Quick answer
Hackers are exploiting CVE-2026-65400 in macOS Screen Sharing to gain root access and deploy Monero miners.
The Dutch National Cyber Security Centre (NCSC) reported widespread macOS attacks exploiting a Screen Sharing vulnerability. Hackers leverage CVE-2026-65400 to gain root access to systems with port 5900 open and deploy Monero cryptocurrency miners.
The flaw enables authentication bypass, allowing arbitrary actions: launching apps, altering security settings, and accessing files. Attacks target systems where Screen Sharing is internet-exposed, simplifying exploitation.
Apple has released patches for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Updates strengthen credential verification and block unauthorized authentication attempts. Users unable to update immediately should disable Screen Sharing or restrict port 5900 access.
Attack scope and geography remain undisclosed. However, NCSC confirms all detected incidents involve Monero mining, though the flaw could potentially be repurposed for other malicious activities.
Common questions
- Which vulnerability is being exploited in macOS attacks?
- Attackers are exploiting CVE-2026-65400 in the Screen Sharing feature, enabling authentication bypass and root-level system access.
- Which macOS versions are vulnerable?
- The flaw affects macOS Tahoe up to 26.6.1, as well as earlier Sequoia and Sonoma releases. Apple has issued patches for all affected versions.
- How can users protect against this attack?
- Update to the latest macOS version or disable Screen Sharing if unused. Block external access to port 5900 to mitigate risks.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml