macOS Screen Sharing Flaw Exploited to Deploy Monero Miner
TL;DR. The Netherlands' NCSC warns hackers are actively exploiting a macOS Screen Sharing vulnerability, CVE-2026-65400, to install Monero cryptocurrency miners. - The flaw allowed network-based attackers to gain root access on systems with exposed port 5900 without valid credentials. - Apple addressed the vulnerability on August 6 in macOS Tahoe 26.6.1 and other recent operating system updates. - Users unable to update immediately can disable the Screen Sharing feature to mitigate the risk of compromise.
- Hackers exploit macOS Screen Sharing vulnerability CVE-2026-65400.
- The flaw allows unauthorized root access and Monero miner deployment.
- Apple patched the issue in macOS Tahoe 26.6.1 and other updates.
- The Netherlands' NCSC issued a warning about active exploitation.
Sources
- Hackers exploit macOS Screen Sharing flaw to deploy Monero miner — bleepingcomputer.com