Critical macOS Screen Sharing Flaw Exploited to Deploy Monero Miner

A recently patched vulnerability in Apple’s macOS has been actively exploited to deploy cryptocurrency mining software on internet-exposed systems. The Netherlands National Cyber Security Centre (NCSC) has issued a warning regarding this issue.

The flaw, identified as CVE-2026-65400 with a CVSS score of 9.8, is a critical authentication vulnerability within the Screen Sharing component. This vulnerability allows attackers on the same network to authenticate to the remote desktop service without valid credentials. Apple addressed this issue by improving state management mechanisms to enforce proper credential validation, releasing updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 earlier this month.

Apple acknowledged the issue in an advisory dated August 6, 2026, crediting security researcher Alfredo Pesoli of Bynario for the discovery and reporting of the flaw. The NCSC-NL has reported active exploitation of this vulnerability, noting instances where systems with port 5900 accessible from the internet were compromised. In these cases, attackers gained root access and installed Monero cryptocurrency miners on the affected systems.

Further analysis by security researcher @osxreverser suggests that the core issue lies in a pre-authentication vulnerability within the Screen Sharing daemon (screensharingd). This flaw potentially allows unauthorized access to any Mac with Screen Sharing enabled, provided the attacker knows the system’s IP address.

In light of these developments, macOS users are strongly advised to update their systems to the latest versions to mitigate this vulnerability. Additionally, users should consider disabling Screen Sharing if it is not in use and ensure that port 5900 is not exposed to the internet to prevent unauthorized access.

This incident underscores the importance of timely software updates and vigilant system configuration to protect against emerging threats. As attackers continue to exploit vulnerabilities for financial gain, maintaining robust security practices remains crucial for safeguarding systems and data.