Hackers are actively exploiting a macOS Screen Sharing flaw to bypass authentication, gain root access and install Monero cryptocurrency miners, according to the Netherlands’ National Cyber Security Centre.
Apple fixed the vulnerability, tracked as CVE-2026-65400, on 6 August. However, public exploit code has since emerged, and attackers have started targeting exposed systems.
Flaw allows access without credentials
The macOS Screen Sharing flaw affects Apple’s built-in remote desktop feature, which uses the VNC protocol over TCP port 5900.
Screen Sharing lets users control a Mac remotely across a network. However, CVE-2026-65400 allows a network-based attacker to access vulnerable systems without valid credentials.
Once inside, an attacker could open applications, view or access files, change security settings and carry out other actions remotely.
Apple addressed the issue by improving state-management mechanisms that enforce correct credential validation and block rogue authentication attempts.
Internet-exposed Macs targeted in attacks
The Dutch NCSC said it received reports of active exploitation against multiple systems with port 5900 exposed to the internet.
In every reported case, the attackers gained root-level access and placed a Monero crypto miner on the compromised Mac.
The agency did not disclose when the attacks began, how many systems attackers compromised or whether the campaign involved activity beyond cryptocurrency mining.
Still, the report shows that attackers are moving quickly to exploit the macOS Screen Sharing flaw after public code became available.
Update macOS as soon as possible
Apple has released security updates for supported macOS versions. Users should upgrade to one of the following releases as soon as possible:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
Users who cannot apply updates immediately should disable Screen Sharing if they do not need the feature.
To do this, open System Settings, select General, then Sharing, and turn off Screen Sharing.
Organisations should also check whether TCP port 5900 is accessible from the public internet. Restricting remote desktop services to trusted networks or VPN connections can reduce exposure while teams deploy the latest patches.


0 responses to “Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner”