A critical flaw in Apple's built-in Screen Sharing feature has been actively exploited by hackers to commandeer Macs and use them to mine Monero ($XMR), according to Dutch cybersecurity autho
A critical flaw in Apple's built-in Screen Sharing feature has been actively exploited by hackers to commandeer Macs and use them to mine Monero ($XMR), according to Dutch cybersecurity authorities.
What the Vulnerability Does
The flaw, tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10 and lets attackers execute code remotely without valid credentials. It targets screensharingd, the system daemon that powers macOS's built-in remote desktop feature. Crucially, CVE-2026-65400 is a pre-authentication flaw, meaning the bypass occurs before the daemon reaches any authentication controls. That makes conventional defences useless: rotating the VNC password, disabling legacy VNC password access, or removing approved Screen Sharing user accounts all have zero effect on this vulnerability.
Any Mac with Screen Sharing enabled and port 5900 open to the internet is at risk. When a Mac user turns Screen Sharing on, the built-in macOS firewall automatically opens that port. Most home routers and dedicated firewalls block port 5900 by default, but if a network has been configured to allow it through, intentionally or otherwise, the machine becomes reachable from anywhere on the internet. Security firm Huntress estimated tens of thousands of Macs were potentially exposed, many of them machines rented by the hour from hosting companies.
Attacks Confirmed, Patch Available
The Netherlands' National Cyber Security Centre (NCSC) confirmed the attacks are not theoretical. In an update to its advisory, the NCSC said it received a report indicating active abuse of the vulnerability across multiple systems on which port 5900 was accessible from the internet, and that in all confirmed cases root access had been obtained and a Monero crypto miner placed on the device. The agency has not disclosed the number of machines affected or further details on the attackers.
The choice of Monero is deliberate. Monero has been a long-standing target of cryptojacking, where mining software is run on hijacked computers, given the token's ability to be mined on ordinary hardware rather than specialised rigs and the private nature of its transactions. U.S. officials subsequently re-rated the flaw's severity: CISA initially scored the vulnerability 7.1 out of 10 on the day Apple shipped the fix, then replaced that rating with a 9.8, near the top of the 10-point scale.
Apple patched the vulnerability on August 6. The only fixes are updating to macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9, or disabling Screen Sharing entirely. Users who have not yet applied the update should do so immediately. Security experts also advise disabling Screen Sharing when not in use, ensuring port 5900 is not exposed to the internet, and connecting via VPN or SSH tunnelling as safer alternatives.
Sources:Bleeping Computer: Hackers exploit macOS Screen Sharing flaw to deploy Monero minerSC World: macOS screen sharing vulnerability actively exploited for crypto miningThe Hacker News: Apple macOS Screen Sharing Flaw Exploited to Install Monero Miner