Apple has fixed a macOS Screen Sharing vulnerability that hackers have been using to mine Monero on open Macs.

An updated warning by the Netherlands’ National Cyber Security Centre said Apple patched a macOS Screen Sharing vulnerability attackers exploited to gain root access and install Monero mining software on exposed Macs connected to the Internet.
On August 12, the Dutch National Cyber Security Centre reported that it had observed CVE-2026-65400 in use, targeting multiple systems connected to the internet through port 5900. In every instance it had seen, the attacker would have had root access and subsequently installed a Monero miner. The NCSC did not say how many devices were affected by the activity, nor did it name a group.
On August 6, Apple released an update for macOS Tahoe, Sequoia, and Sonoma to address the flaw. The Screen Sharing flaw is a state management error that could allow a network-based attacker to bypass authentication via the service.
Security company Huntress reported that a flaw in the SCRAM (Secure Remote Password) authentication mechanism could allow an unauthenticated connection to be treated as an authenticated connection, allowing for a privilege escalation. As the flaw occurs prior to normal authentication, changing passwords or disabling accounts does not reduce the vulnerability.
Huntress suggested applying Apple’s security updates or disabling Screen Sharing until vulnerable hosts can be updated. Researcher Ryan Dowd did a search on Censys and found tens of thousands of exposed hosts, although this number does not represent the number of infected hosts.
Read More: Zcash Is Making a Comeback: Why ZEC Could Lead Crypto’s Privacy Revival
Hosted bare-metal Macs are especially at risk, as remote Mac provisioning may leave Screen Sharing enabled on freshly provisioned machines. The vulnerability was given a CVSS severity score of 9.8 by CISA. No privileges or user interaction are required to exploit.
According to the Dutch NCSC, in these attacks, the attackers compromised these Macs to use their processing power to mine Monero (rather than stealing wallets). Once the attackers had root access to the compromised Macs, they used the Macs’ processing power to mine Monero. These addresses have not been reported: the miner and mining-pool address, the attackers’ wallets, or the amount of XMR▼$507.83 mined.
Read More: How Digital Platforms are Redefining Trust in Online Finance
Monero’s popularity for cryptojacking, due to its mineability on general purpose hardware, has resulted in it being frequently abused in this manner. It is part of a broader trend of cryptocurrency attacks on macOS, including both crypto-jacking and malware targeting cryptocurrency companies.
At the time of this writing, XMR traded around $417 and appreciated by around 2% against the dollar in 24 hours. Over seven days, XMR appreciated by nearly 6.7%, not reflecting the mining campaign’s size or returns.
Security vendor Huntress noted that the best mitigation for this vulnerability is to patch vulnerable Mac systems, especially ones exposing the Screen Sharing ports directly to the Internet, even if administrators believe it is disabled.
As the campaign is not yet proved, and there are no published public indicators of compromise for the mining infrastructure, later incident response may show how long CVE-2026-65400 was active before the patch was released.
