Hackers Exploit macOS Screen Sharing Flaw to Install Cryptocurrency Miners
A serious security vulnerability in macOS's Screen Sharing feature has been actively exploited by attackers, according to a new report. The flaw, identified as CVE-2026-65400, allows an attacker on the network to authenticate without valid credentials, gaining full remote control over the Mac's screen, keyboard, and mouse. Apple patched the vulnerability earlier this month by changing the authentication management system, but attackers have already exploited unpatched systems with Screen Sharing accessible via the internet, particularly through port 5900.
The Dutch National Cyber Security Centre reported multiple cases where attackers obtained root access and installed Monero cryptocurrency miners on compromised Macs. This malware uses the victim's hardware resources to mine cryptocurrency without their knowledge. Apple released security updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, with the Tahoe update issued on August 6. By August 12, proof-of-concept exploit code was publicly available, and active exploitation was confirmed.
The vulnerability carries a CVSS score of 7.1, indicating high severity, especially for Macs with Screen Sharing enabled and exposed directly to the internet. Users are urged to immediately update their systems via System Settings and ensure port 5900 is not publicly accessible. Even updated systems should be checked for signs of prior compromise, as the patch prevents new exploits but does not remove existing malware.