Attackers exploit macOS Screen Sharing flaw to deploy miners

Attackers exploit CVE-2026-65400 in macOS Screen Sharing to gain root access and install Monero miners, the Dutch NCSC reported.

Attackers are actively exploiting CVE-2026-65400, a recently patched authentication flaw in macOS Screen Sharing, to gain root access and install Monero cryptominers, the Dutch National Cyber Security Centrum (NCSC) reported. Apple disclosed the vulnerability on August 6 and issued fixes in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

Roughly a week after Apple released the updates, the NCSC reported that in-the-wild exploitation had started. The agency noted the availability of a public proof-of-concept exploit and the presence of systems with port 5900 exposed to the internet as factors in active abuse. “The NCSC has received a notification showing that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the internet,” the agency reported.

CVE-2026-65400 is an authentication bug in the Screen Sharing service that can allow a remote actor to log in without valid credentials. AI security firm Calif wrote: “Naming an account is the one thing the bug needs. It is not much of a barrier. A username is not a secret, and macOS prints them on the login window.” After authentication, attackers have been observed obtaining root privileges and deploying a Monero mining payload.

Apple’s update for the Screen Sharing service changes state management to improve credential validation and block unauthorized authentication attempts, the NCSC noted. Security firms and national agencies advised applying the updates to devices with Screen Sharing enabled, particularly those reachable from the internet.

Researchers flagged additional recent fixes to screensharingd, the daemon that manages Screen Sharing connections. In late July Apple patched at least four other issues in that daemon, three of which received CVE identifiers. Independent researcher osxreverser reported that a silently addressed fix appeared to be the most severe, as it could allow unauthenticated remote code execution as root on systems where System Integrity Protection (SIP) was disabled. The researcher also reported roughly 40,000 internet-accessible macOS systems had Screen Sharing enabled.

Technical analysis shows variants of these flaws can be exploited without user interaction. Some attacks have planted a reverse shell and added a root crontab during the same connection to maintain persistence. The primary impact observed in the current wave tied to CVE-2026-65400 is installation of a Monero miner on compromised systems.

Articles by this author