Mac Users Warned as Critical Screen Sharing Flaw Exploited for Monero Mining
Cybercriminals have been exploiting a critical vulnerability in Apple's macOS Screen Sharing functionality to gain full control of internet-connected Mac systems and deploy Monero mining malware. The Netherlands' National Cyber Security Centre (NCSC) confirmed active attacks targeting Macs with port 5900 exposed online.
The vulnerability, designated as CVE-2026-65400, was addressed by Apple through security patches released on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. However, traditional mitigation methods such as password resets are ineffective against this exploit.
Cybersecurity firm Huntress discovered that malicious actors could manipulate the system into recognizing an unauthorized connection as pre-authenticated, thereby granting complete elevated access. The threat level is particularly elevated for cloud-hosted bare-metal Mac infrastructure, where Screen Sharing is often enabled by default on freshly provisioned machines.