MacOS Users Warned of Active Exploitation of Screen Sharing Flaw, Cryptocurrency Mining Attacks Emerge
A critical security flaw in macOS’s built-in remote desktop feature has been actively exploited by hackers to gain unauthorized access to computers and deploy cryptocurrency mining malware. The vulnerability, which was patched by Apple just last week, allows attackers to bypass authentication checks and gain root access to the system.
The issue lies in macOS Screen Sharing, a feature that enables remote desktop control over a network using the VNC protocol. Normally, this feature requires valid credentials to establish a connection, but hackers have discovered a way to exploit the vulnerability and gain access without needing to authenticate. This allows them to open applications remotely, access files, change security settings, and perform other malicious actions.
According to the Netherlands’ National Cyber Security Centre (NCSC), which issued an advisory on the issue, attackers have been exploiting this vulnerability in attacks where port 5900 is exposed to the internet. In one reported case, the hacker obtained root access to the system and deployed a Monero cryptocurrency miner, highlighting the potential for significant financial losses.
The NCSC recommends that all macOS users upgrade their systems to one of the latest patches, which include improvements to state management mechanisms to prevent rogue authentication attempts. For those who cannot immediately update, disabling Screen Sharing via System Settings can provide an interim solution.
It’s essential for MacOS users to be aware of this vulnerability and take immediate action to protect themselves. Even with the patch in place, attackers may still find ways to exploit other vulnerabilities or use social engineering tactics to gain access. To mitigate the risk, it’s crucial to keep software up-to-date, use strong passwords, and be cautious when granting remote access permissions.
As the cybersecurity landscape continues to evolve, it’s clear that even seemingly secure systems can have hidden weaknesses. This incident serves as a reminder for users to stay vigilant and take proactive steps to protect their devices from exploitation.
Source: Bleeping Computer — 2026-08-14