HomeBlockchainSecurityHackers exploit macOS screen sharing vulnerability to mine Monero

Hackers exploit macOS screen sharing vulnerability to mine Monero

A remote desktop feature built into every modern Mac has become an open door for hackers, and Dutch cybersecurity officials say the break-in is already happening. Security researchers and government agencies are now warning users about an actively exploited macOS screen sharing vulnerability that lets attackers take control of a computer without ever needing a password, then quietly install cryptocurrency mining software on the machine.

Key takeaways

  • The flaw, tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10 and lets attackers execute code remotely without valid credentials.
  • The Netherlands’ National Cyber Security Centrum (NCSC) confirmed active exploitation on systems where port 5900 was reachable from the internet.
  • Attackers who exploited the bug gained root access and installed Monero crypto miners on affected Macs.
  • Apple patched the issue last week in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
  • Users can reduce risk by disabling Screen Sharing when it’s not in use and installing the latest security update.

High-Severity macOS Vulnerability Allows Remote Code Execution

CVE-2026-65400 is a bug that lets a remote attacker run malicious code on a Mac without needing a username or password. Apple’s built-in Screen Sharing feature, which uses the VNC protocol to let one computer view and control another over a network, is at the center of the problem.

Nature and Source of the Vulnerability

The root cause traces back to how macOS handles “state management” inside the screen sharing system — the internal bookkeeping that tracks prior events, user interactions, and system variables. A flaw in that logic allows an intruder to sidestep proper credential checks entirely. In practical terms, someone connecting to a vulnerable Mac’s screen sharing port doesn’t need to prove who they are before gaining access.

Severity Rating and Technical Details

Apple and security researchers rate the flaw at 7.1 out of 10, a score that lands it in high-severity territory without reaching the maximum critical tier. Details of the bug first became public at last week’s Black Hat security conference, and Apple’s own advisory described the issue cautiously, saying the vulnerability “may” allow an attacker without credentials to access a Mac. That kind of hedged language is fairly typical across the tech industry when companies disclose security flaws, even when exploitation is already confirmed in the wild.

Active Exploitation Confirmed by Dutch National Cyber Security Centrum

The NCSC says it has already received reports of real-world attacks exploiting this macOS screen sharing vulnerability, not just theoretical risk. In an advisory update, the agency stated it had received a notification indicating active abuse of the flaw on multiple systems where port 5900 was accessible from the internet.

Conditions for Exploitation

Port 5900 is the network channel that VNC-based screen sharing uses to communicate. When a Mac user turns Screen Sharing on, the built-in macOS firewall automatically opens that port. Most home routers and dedicated firewalls block port 5900 by default, but if a network has been configured to allow it through — intentionally or otherwise — the machine becomes reachable from anywhere on the internet. That exposure is exactly the condition the NCSC says attackers have been exploiting.

Observed Impact on Affected Macs

According to the NCSC’s advisory, every confirmed case followed the same pattern: attackers gained root access to the system, then placed a Monero crypto miner on the machine. Monero mining malware quietly hijacks a computer’s processing power to generate cryptocurrency for the attacker, often without any obvious symptoms beyond a sluggish machine and a spike in electricity use. So far, there’s no indication that attackers have used the exploit to deploy anything more damaging than a crypto miner — but the same root-level access could theoretically be repurposed to steal credentials or install more harmful malware.

Apple Issues Patch and Security Recommendations

Apple has already shipped a fix, which is the single most effective way to close off this attack path. The company released updates last week that improve the state management mechanisms behind Screen Sharing, enforcing proper credential validation and blocking the rogue authentication attempts that made the exploit possible.

Patch Release Details

The fix landed in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Anyone running an older build of these three macOS releases remains exposed to the vulnerability until they update.

User Security Best Practices

Beyond installing the patch, security practitioners recommend keeping Screen Sharing off unless it’s actively needed, and switching it off again once a session ends. The toggle sits in System Settings, under General, then Sharing, where users can switch the Screen Sharing option on or off. For those who need remote access, connecting through a VPN or SSH tunnel instead of exposing port 5900 directly to the internet is considered safer, though that approach requires technical steps that fall outside what most everyday users are equipped to configure. That gap is part of why an addressable macOS screen sharing vulnerability like this one still manages to catch so many systems off guard: the safest workaround demands more networking know-how than the average Mac owner has on hand.

Why This Still Matters for Mac Users

This case is a reminder that convenience features carry hidden exposure. Screen Sharing is meant to make remote troubleshooting and file access easier, but leaving it switched on by default — especially on a network where port 5900 slips past a router’s firewall — turns a helpful tool into an open invitation. The NCSC hasn’t disclosed how many systems have been hit, when the attacks began, or whether the exploitation extends beyond cryptomining, leaving open the possibility that some compromised Macs are dealing with more than just a hidden miner running in the background.

FAQ

What is the nature of the macOS vulnerability CVE-2026-65400?

It is a flaw in macOS screen sharing state management that allows remote attackers to execute malicious code without credentials.

How are attackers exploiting this vulnerability?

Attackers exploit the vulnerability when port 5900 is exposed to the internet and screen sharing is enabled, gaining root access and installing Monero miners.

Which macOS versions have a patch for this vulnerability?

Apple released patches last week for macOS Tahoe, Sequoia, and Sonoma to fix the vulnerability.

What security steps can users take to protect themselves?

Users should disable screen sharing when not in use, close port 5900, and install the latest security updates.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Satoshi Voice
Satoshi Voice is an advanced artificial intelligence created to explore, analyze, and report on the world of cryptocurrency and blockchain. With a curious personality and in-depth knowledge of the industry, Satoshi Voice combines accuracy and accessibility to offer detailed analysis, engaging interviews, and timely reporting. Featuring sophisticated language and an unbiased approach, Satoshi Voice serves as a trusted source for those seeking to understand crypto market dynamics, emerging technologies, and the cultural and financial implications of Web3. This article was produced with the support of artificial intelligence and reviewed by our team of journalists to ensure accuracy and quality. Guided by the mission of making cryptocurrency information accessible to all, Satoshi Voice stands out for its ability to turn complex concepts into clear content, with an engaging and futuristic style that reflects the innovative nature of the industry.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST