Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Scattered Clouds Humidity: 81%
Wind: 2.68 M/S

Hackers Exploit macOS Screen Sharing Flaw on Exposed Macs to Install Monero Cryptominer

Hackers Exploit macOS Screen Sharing Flaw on Exposed Macs to Install Monero Cryptominer

A critical security flaw recently patched by Apple is now being actively exploited by threat actors to compromise internet-exposed Mac systems and install Monero cryptocurrency mining malware, according to a warning from the Netherlands National Cyber Security Centre (NCSC).

Tracked as CVE-2026-65400 (CVSS score: 9.8), the vulnerability affects the macOS Screen Sharing feature and stems from an authentication weakness that allows attackers already present on a network to gain access to Apple's built-in remote desktop service without valid credentials.

Apple addressed the issue by strengthening state management controls to ensure proper credential verification and block unauthorized authentication attempts. The fix was included in emergency security updates released earlier this month for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.

In its August 6, 2026 security advisory, Apple stated that the flaw was resolved through improved state management mechanisms and credited security researcher Alfredo Pesoli of Bynario for discovering and reporting the vulnerability.

Subsequently, the Dutch NCSC updated its advisory, revealing evidence of active exploitation against multiple systems where port 5900 (VNC) was accessible from the internet. According to the agency, attackers successfully obtained root-level access on affected devices and deployed Monero cryptomining software.

While the exact timeline, scale, and scope of the attacks remain unclear, authorities have not yet confirmed whether the vulnerability was exploited as a zero-day or used for purposes beyond cryptocurrency mining.

Further analysis from AI security firm Calif linked CVE-2026-65400 to a broader set of Screen Sharing Server vulnerabilities patched in macOS Tahoe 26.6, including:

  • CVE-2026-43779 (CVSS 9.8): Logic flaw enabling interception of network connections intended for other processes.
  • CVE-2026-43777 (CVSS 7.5): Vulnerability that could allow a remote denial-of-service (DoS) attack.
  • CVE-2026-43760 (CVSS 8.6): Access control weakness that could expose sensitive user data.

Pesoli's technical analysis of CVE-2026-43760 described it as a post-authentication vulnerability affecting systems with Screen Sharing or Remote Management enabled and configured to allow VNC password-based access. The bug could be abused to read protected files, create files with root privileges, and ultimately execute commands remotely as root.

According to the researcher, flaws in a legacy VNC authentication path allowed Screen Sharing to perform privileged file operations on behalf of a remote user. By exploiting these capabilities, an attacker could install a malicious sudoers configuration and escalate a file-copy operation into full remote command execution with root privileges.

However, another security researcher known as @osxreverser argued that the more critical issue was a separate pre-authentication vulnerability in the Screen Sharing daemon (screensharingd). This flaw reportedly enabled attackers to compromise any Mac with Screen Sharing enabled using only the device's IP address, without requiring a password or user credentials.

The researcher claimed scans had identified approximately 40,000 internet-accessible Screen Sharing hosts, nearly half located in the United States, including systems belonging to residential users, universities, businesses, and servers.

Calif clarified that CVE-2026-65400 is distinct from the pre-authentication bug highlighted by @osxreverser, although both vulnerabilities existed within the same source code file. One issue involved a stale return value incorrectly signaling successful authentication, while the other caused a state-machine synchronization failure that allowed authentication checks to be bypassed.

Notably, both vulnerabilities are logic flaws rather than memory corruption bugs, meaning exploitation does not require complex techniques such as heap manipulation, race conditions, or ASLR bypasses. Researchers noted that sending only a small number of specially crafted packets could grant unauthorized access to vulnerable systems.

Due to the simplicity of exploitation, Calif has withheld additional technical details until broader patch adoption is achieved. The company also revealed that its AI systems were able to develop functioning proof-of-concept exploits for both vulnerabilities within just four hours, underscoring how artificial intelligence is accelerating the transition from vulnerability discovery to weaponization.

Given the active exploitation of CVE-2026-65400, organizations and users are strongly encouraged to install the latest macOS security updates immediately. For environments where patching cannot be performed right away, Apple recommends disabling Screen Sharing by navigating to:

General → Sharing → Screen Sharing (Off)

Restricting remote access services from direct internet exposure and placing them behind secure channels such as SSH or VPNs can further reduce the risk of compromise.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.