Hackers Exploit macOS Screen Sharing Flaw to Mine Monero
Dutch cyber agency warns attackers are exploiting a macOS Screen Sharing authentication flaw on internet-exposed port 5900 systems, gaining root access to install Monero miners. Apple patched the issue in recent macOS updates, but unpatched users remain exposed to cryptojacking and performance loss.
Quick Take
NCSC reports active exploitation of macOS Screen Sharing vulnerability.
Attackers gain root access via port 5900, install Monero miners.
Flaw CVE-2026-65400 rated 7.1, patched in latest macOS updates.
Users with exposed Screen Sharing should update immediately.
Market Impact Analysis
NeutralThe article centers on a macOS security flaw and Monero mining malware; it has no direct price catalyst for crypto markets, mainly affecting victim systems and privacy coin mining activity.
Speculation Analysis
Key Takeaways
- Dutch NCSC confirms active exploitation of macOS Screen Sharing flaw CVE-2026-65400, allowing root access without valid credentials.
- Attackers target internet-exposed port 5900 to install Monero miners on compromised Macs, draining performance and electricity.
- Apple released patches in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 to fix the authentication flaw.
- Users with Screen Sharing enabled and reachable from the internet should update immediately or disable exposure.
What Happened
Attackers are actively exploiting a macOS Screen Sharing authentication flaw tracked as CVE-2026-65400 to seize root control of internet-exposed Macs and install Monero miners. The Dutch National Cyber Security Center (NCSC) reported multiple incidents across systems with port 5900 open to the internet. Public proof-of-concept code is circulating, lowering the barrier for additional attacks. Apple has already patched the vulnerability in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, but unpatched systems remain exposed. Compromised machines suffer degraded performance and increased electricity costs as miners run hidden in the background. Users with Screen Sharing accessible externally are the primary targets.
The Numbers
CVE-2026-65400 carries a severity score of 7.1 out of 10. The attack vector is port 5900, the default for macOS Screen Sharing. In confirmed cases, attackers gained root access—the highest privilege level—on multiple systems. Patch coverage spans three macOS releases: Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The malicious payload is a Monero mining program, which harnesses victim CPU/GPU power. Port 5900 exposure to the open internet was common across compromised hosts. No financial losses from stolen funds are reported; costs come from performance degradation and energy consumption.
Why It Happened
The root cause is faulty state management during authentication in Screen Sharing. Network attackers could send crafted authentication attempts that were incorrectly accepted, bypassing valid credential checks. Internet-wide scans for open port 5900 make exposed Macs easy to discover. Monero remains the coin of choice for cryptojacking because its privacy features obscure transaction trails, letting attackers cash out without easy traceability. Public exploit code further fuels the campaign, enabling low-skill attackers to replicate the attack. Apple's patch adds stricter validation, but many users delay updates or leave remote access services exposed.
Broader Impact
This incident highlights ongoing cryptojacking trends targeting macOS, which was once considered less vulnerable than Windows. Monero's privacy design continues to attract malware operators. The campaign adds to a wave of schemes using pirated software, fake CAPTCHAs, and malicious apps. For enterprises, exposed remote management ports are a systemic risk. Timely patch management and network segmentation are critical defenses.
What to Watch Next
- Check if your Mac runs Screen Sharing and whether port 5900 is reachable from the internet. Disable exposure immediately.
- Apply Apple's latest macOS updates—Sequoia 15.7.9, Sonoma 14.8.9, or Tahoe 26.6.1—to patch the flaw.
- Monitor for unusual CPU usage or unexpected processes like xmrig, which may indicate cryptojacking.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.