CybersecurityAugust 15, 2026· via Security Affairs

macOS Screen Sharing flaw exploited to install Monero miners

macOS Screen Sharing flaw exploited to install Monero miners

Image : Security Affairs

Hackers are exploiting a critical macOS authentication bypass flaw to install Monero miners on unpatched systems running Screen Sharing with port 5900 exposed online. The Dutch National Cyber Security Centre (NCSC-NL) confirmed active exploitation of CVE-2026-65400, just days after Apple released patches for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

A textbook race against time

The vulnerability resides in macOS’s built-in Screen Sharing feature, where improper state management during authentication allows attackers on the same network—or even the internet—to bypass credentials entirely. According to Apple’s advisory, an attacker “may be able to authenticate to Screen Sharing without valid credentials.” The NCSC-NL reported seeing active exploitation targeting systems where port 5900, the default port for Screen Sharing, was directly reachable. In every confirmed case, attackers gained root access and deployed a Monero cryptocurrency miner.

Simplicity that raises alarms

Security researchers noted that this flaw, along with two others patched last month, stems from straightforward logic errors rather than complex memory corruption or race conditions. In fact, one firm demonstrated how an AI coding assistant could generate a working exploit in under four hours—a timeline that underscores how quickly attackers can weaponize even patched vulnerabilities. Earlier this year, another researcher claimed to have found nearly 40,000 exposed Screen Sharing hosts online, with half in the U.S., spanning residential, academic, and corporate networks.

Why it matters

This incident highlights the shrinking window between patch release and exploit deployment, a trend that challenges defenders to prioritize rapid patching and network segmentation. While the payload so far has been relatively mundane—Monero mining—the potential for root access opens the door to far more damaging attacks. For Mac users, the lesson is clear: enabling Screen Sharing without strict access controls or exposing port 5900 to the internet invites unnecessary risk.


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home