AI Builds MacOS Exploit In 4 Hours, Opening Door To Monero Mining

A patched macOS Screen Sharing flaw is being exploited as AI speeds working attack development (Image: Shutterstock)
A patched macOS Screen Sharing flaw is being exploited as AI speeds working attack development (Image: Shutterstock)

Attackers are exploiting a macOS Screen Sharing flaw patched by Apple to gain root and install Monero (XMR) miners, while an AI agent built working exploits in four hours.

Key Points:

  • Attackers are abusing CVE-2026-65400 on exposed Macs to gain root access and install Monero miners.
  • Calif says an AI agent produced working exploits for two pre-authentication root bugs in four hours.
  • Apple has patched the flaw, while Dutch and U.S. agencies differ sharply on its CVSS severity.

Monero macOS Exploit

The Dutch National Cyber Security Center said Aug. 12 that it had received reports of active exploitation of CVE-2026-65400 on Macs exposing port 5900 to the internet. Every confirmed case followed the same pattern.

The agency said “root had been accessed” and “a Monero crypto miner had been placed,” while Apple describes the bug as an authentication issue fixed through improved state management in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

Security researcher osxreverser said roughly 40,000 Screen Sharing hosts were reachable from the internet, nearly half in the United States, with many on residential connections. The number of compromised Macs remains unknown. Until patched, users should disable Screen Sharing or block port 5900.

Also Read: Anthropic Outpaces OpenAI By $25B As Revenue Momentum Accelerates

Calif AI Exploit

Calif reverse-engineered Apple’s out-of-band update and used an AI agent to produce working exploits for two separate pre-authentication remote root bugs. The process took four hours. The firm said it is withholding technical details for CVE-2026-65400 until most Macs are patched because producing the exploit was too easy.

Ars Technica noted that root access could be used for credential theft rather than mining, and no public evidence currently confirms abuse beyond cryptomining.

The Dutch agency rates CVE-2026-65400 at 7.1 under CVSS v3, while CISA assigned 9.8 through the enrichment program feeding the National Vulnerability Database, a 2.7-point gap between national agencies.

NIST has not issued its own score, and a separate 9.6 figure reported elsewhere does not match the cited national sources.

Apple published its advisory Aug. 6 and credited Alfredo Pesoli of Bynario, while the Dutch agency issued its first warning Aug. 7 and revised it Aug. 12 after a public proof of concept appeared and active abuse was reported. That public patch-to-abuse timeline spanned six days.

Read Next: Jane Street’s $15B Loss Puts Its $990M Bitcoin ETF Holdings In Focus

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

page_article_disclaimer
page_blogs_view_latest
Show All News
AI Builds MacOS Exploit In 4 Hours, Opening Door To Monero Mining | Yellow