Monero Miners Hit Macs Through Apple Screen Sharing Authentication Flaw

A patched Screen Sharing flaw allowed attackers to seize exposed Macs and install Monero miners (Image: Shutterstock)
A patched Screen Sharing flaw allowed attackers to seize exposed Macs and install Monero miners (Image: Shutterstock)

Hackers are exploiting an Apple macOS Screen Sharing vulnerability to gain root access on exposed Macs and install Monero (XMR) mining software.

Key Points:

  • Dutch authorities observed active exploitation of CVE-2026-65400 on Macs exposing Screen Sharing through port 5900.
  • Attackers gained root access and installed Monero miners, while public proof-of-concept code is now available.
  • Apple patched the authentication flaw in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

macOS Monero Attack

The Netherlands’ National Cyber Security Center said Aug. 12 that it received reports of active exploitation across multiple Macs, with attackers gaining root privileges and installing Monero mining software. All were exposed through port 5900.

The vulnerability, tracked as CVE-2026-65400, carries a CVSS severity score of 7.1 and stems from faulty state management during the Screen Sharing authentication process. No valid password was required.

Apple strengthened its validation checks and released fixes Aug. 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. The NCSC also said public proof-of-concept code is circulating, lowering the barrier for attackers targeting systems that still expose Screen Sharing to the internet. Unpatched Macs remain at risk.

Also Read: Vitalik Buterin Backs Bitcoin Model For 128 KB Ethereum Payment Proofs

Monero Cryptojacking Risk

The campaign is a cryptojacking operation, in which attackers use someone else’s computing resources to mine cryptocurrency while keeping the rewards generated by the compromised hardware. The costs fall on the victim.

Monero remains attractive for this type of abuse because its privacy features make transfers harder to trace than activity on transparent blockchains.

That gives attackers a way to convert sustained access to compromised hardware into mining revenue that is more difficult to follow.

Bitdefender recently found pirated copies of “The Odyssey” carrying Lumma Stealer, while other reported campaigns used fake CAPTCHA pages, SparkKitty mobile apps, gaming-themed wallpapers and compromised Python packages. Some attacks also routed malicious pages through BNB Chain. The methods keep changing.

Cryptojacking has repeatedly centered on Monero because attackers can spread mining across many hijacked devices without directly stealing funds from a victim’s wallet. The entry point is different. The underlying model remains the same, compromise hardware, consume its resources and route the mining rewards to an attacker-controlled destination.

Read Next: OpenAI Reportedly Scrapped Its 3rd Safety Team Ahead Of A Public Listing

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News
Monero Miners Hit Macs Through Apple Screen Sharing Authentication Flaw | Yellow