macOS Screen Sharing Exploit Enables Root Access and Monero Mining
TL;DR. Threat actors are exploiting a recently patched macOS Screen Sharing vulnerability, CVE-2026-65400, to gain root access and install Monero miners on vulnerable systems. - The high-severity bug allows remote attackers to log in without valid credentials, impacting macOS Tahoe, Sequoia, and Sonoma. - Apple released fixes on August 6, but exploitation began roughly a week later, fueled by a public proof-of-concept. - The Dutch NCSC warned of active abuse on systems where port 5900 was internet-accessible.
- Threat actors are actively exploiting CVE-2026-65400 in macOS Screen Sharing.
- The vulnerability grants remote attackers root access to compromise systems.
- Exploitation leads to the deployment of Monero cryptominers.
- Apple patched the flaw on August 6, but in-the-wild attacks started soon after.
- A public proof-of-concept exploit contributed to the rapid exploitation rate.
Sources
- Recent macOS Screen Sharing Vulnerability Exploited in Attacks — securityweek.com