Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

A Severe macOS Vulnerability is Being Exploited by Hackers to Deploy Cryptocurrency Miners

A critical vulnerability in Apple’s macOS operating system has been discovered and is being actively exploited by hackers. The flaw, which affects Screen Sharing, a built-in remote desktop feature, allows attackers to gain unauthorized access to user systems without valid credentials. What’s more alarming is that the hackers are using this exploit to deploy Monero cryptocurrency miners on compromised machines.

The vulnerability lies in the way macOS handles authentication for remote desktop connections over TCP port 5900. Apple patched CVE-2026-65400, a known flaw, on August 6th with its latest software update, macOS Tahoe 26.6.1 and earlier releases. However, it appears that not all users have applied the patch yet, leaving them vulnerable to attacks.

According to the Netherlands’ National Cyber Security Centre (NCSC), hackers are using this exploit to gain root access to compromised systems and deploy Monero miners. This is a serious concern for macOS users, as attackers can use this access to open applications remotely, access files, change security settings, and perform other malicious actions.

To make matters worse, the NCSC notes that in all reported cases where port 5900 was accessible from the internet, hackers were able to obtain root access and deploy cryptocurrency miners. This highlights the importance of keeping macOS up-to-date with the latest software patches and being cautious when sharing remote desktop connections over insecure networks.

MacOS users are advised to immediately update their systems to one of the following releases: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9. These updates improve state management mechanisms to enforce correct credential validation and prevent rogue authentication attempts. If system updates are not feasible at this time, users can temporarily disable Screen Sharing through System Settings.

The discovery of this vulnerability serves as a reminder that even with built-in security features, macOS is not immune to attacks. Users must stay vigilant and take proactive measures to protect their systems from hackers. By keeping software up-to-date and being cautious when sharing remote desktop connections, users can significantly reduce the risk of falling victim to this exploit.

In light of this vulnerability, it’s essential for all macOS users to take immediate action by updating their systems or disabling Screen Sharing if not needed. This will help prevent attackers from exploiting the flaw and deploying malicious cryptocurrency miners on compromised machines.


Source: Bleeping Computer — 2026-08-14