Technology & InnovationNeutral
47
XMR

Hackers Exploit macOS Screen Sharing Flaw to Mine Monero

Dutch cyber agency warns attackers are exploiting a macOS Screen Sharing authentication flaw on internet-exposed port 5900 systems, gaining root access to install Monero miners. Apple patched the issue in recent macOS updates, but unpatched users remain exposed to cryptojacking and performance loss.

DecryptDecrypt Staff

Quick Take

1

NCSC reports active exploitation of macOS Screen Sharing vulnerability.

2

Attackers gain root access via port 5900, install Monero miners.

3

Flaw CVE-2026-65400 rated 7.1, patched in latest macOS updates.

4

Users with exposed Screen Sharing should update immediately.

Market Impact Analysis

Neutral

The article centers on a macOS security flaw and Monero mining malware; it has no direct price catalyst for crypto markets, mainly affecting victim systems and privacy coin mining activity.

Timeframeshort

Speculation Analysis

Factuality90/100
RumorsVerified
Speculation Trigger15/100
MinimalExtreme FOMO

Key Takeaways

  • Dutch NCSC confirms active exploitation of macOS Screen Sharing flaw CVE-2026-65400, allowing root access without valid credentials.
  • Attackers target internet-exposed port 5900 to install Monero miners on compromised Macs, draining performance and electricity.
  • Apple released patches in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 to fix the authentication flaw.
  • Users with Screen Sharing enabled and reachable from the internet should update immediately or disable exposure.
Severity Rating7.1/10CVE-2026-65400
Exposed Port5900Screen Sharing default
Patched Versions3 releasesSequoia, Sonoma, Tahoe
Access LevelRootHighest control

What Happened

Attackers are actively exploiting a macOS Screen Sharing authentication flaw tracked as CVE-2026-65400 to seize root control of internet-exposed Macs and install Monero miners. The Dutch National Cyber Security Center (NCSC) reported multiple incidents across systems with port 5900 open to the internet. Public proof-of-concept code is circulating, lowering the barrier for additional attacks. Apple has already patched the vulnerability in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, but unpatched systems remain exposed. Compromised machines suffer degraded performance and increased electricity costs as miners run hidden in the background. Users with Screen Sharing accessible externally are the primary targets.

The Numbers

CVE-2026-65400 carries a severity score of 7.1 out of 10. The attack vector is port 5900, the default for macOS Screen Sharing. In confirmed cases, attackers gained root access—the highest privilege level—on multiple systems. Patch coverage spans three macOS releases: Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The malicious payload is a Monero mining program, which harnesses victim CPU/GPU power. Port 5900 exposure to the open internet was common across compromised hosts. No financial losses from stolen funds are reported; costs come from performance degradation and energy consumption.

Why It Happened

The root cause is faulty state management during authentication in Screen Sharing. Network attackers could send crafted authentication attempts that were incorrectly accepted, bypassing valid credential checks. Internet-wide scans for open port 5900 make exposed Macs easy to discover. Monero remains the coin of choice for cryptojacking because its privacy features obscure transaction trails, letting attackers cash out without easy traceability. Public exploit code further fuels the campaign, enabling low-skill attackers to replicate the attack. Apple's patch adds stricter validation, but many users delay updates or leave remote access services exposed.

Broader Impact

This incident highlights ongoing cryptojacking trends targeting macOS, which was once considered less vulnerable than Windows. Monero's privacy design continues to attract malware operators. The campaign adds to a wave of schemes using pirated software, fake CAPTCHAs, and malicious apps. For enterprises, exposed remote management ports are a systemic risk. Timely patch management and network segmentation are critical defenses.

What to Watch Next

  • Check if your Mac runs Screen Sharing and whether port 5900 is reachable from the internet. Disable exposure immediately.
  • Apply Apple's latest macOS updates—Sequoia 15.7.9, Sonoma 14.8.9, or Tahoe 26.6.1—to patch the flaw.
  • Monitor for unusual CPU usage or unexpected processes like xmrig, which may indicate cryptojacking.

Source: Decrypt

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Decrypt
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

🏛️
DeFiBullish
67

Compound Pivots $52 Million to Institutional Lending Push

Compound, a pioneering DeFi lending protocol, is shifting to institutional clients with a $52 million commitment and new leadership. The pivot follows a sharp decline in locked assets from peak levels five years ago, as retail traders lost interest, prompting a strategic realignment toward institutional capital.

COMP
80% confidence
Aug 17, 2026, 3:32 PM UTC · CoinDesk
macOS Screen Sharing Flaw Used to Mine Monero | Bytewit