Apple Fixes Critical macOS Screen Sharing Flaw Exploited for Monero Mining

2 hour ago 3 sources negative

Key takeaways:

  • CISA's 9.8 severity upgrade signals widespread vulnerable endpoints, yet XMR price remains unmoved.
  • Monero's privacy features drive illicit mining demand, reinforcing use case and regulatory risk.
  • Watch for exchange inflows from compromised Mac miners as potential XMR sell pressure.

Apple has patched a critical macOS Screen Sharing vulnerability tracked as CVE-2026-65400 after attackers exploited internet-facing Macs to gain root access and install Monero mining software. The Netherlands’ National Cyber Security Centre confirmed active exploitation in an updated advisory on Aug. 12, stating that in every reported case involving port 5900 exposure, attackers obtained root access and deployed a Monero miner.

The vulnerability stems from improper state management in the Secure Remote Password authentication process used by macOS Screen Sharing. Security firm Huntress found that an attacker could make the service treat an unauthenticated connection as authenticated and obtain privileged access. Because exploitation occurs before normal authentication, changing Screen Sharing passwords, disabling legacy VNC authentication, or removing authorized user accounts does not stop the attack. Apple released fixes on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, and Huntress recommends installing the update or disabling Screen Sharing immediately.

The U.S. Cybersecurity and Infrastructure Security Agency initially rated the flaw 7.1, but upgraded it to a 9.8 critical CVSS score on Aug. 14, with no privileges or user interaction required. Huntress researcher Ryan Dowd said a Censys search identified “tens of thousands of potentially vulnerable hosts,” though that figure reflects exposed Macs rather than confirmed compromises. The risk is especially high for hosted bare-metal Macs, such as remote Mac minis, where Screen Sharing may be enabled on newly provisioned machines before patching.

Dutch officials did not disclose how many Macs were compromised, the mining software, pool addresses, attacker wallets, or resulting XMR proceeds. Monero remains a frequent choice in cryptojacking campaigns because it can be mined with general-purpose computing hardware and offers privacy features that hinder tracing. At press time, Monero traded around $414, with less than 1% movement in 24 hours and about 5% over seven days.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.