Crypto Companies News

Apple Patches Critical macOS Flaw After Hackers Exploit Macs to Mine Monero

Yevheny Serhiienko
17 August 2026 3 min read

Apple has fixed a macOS Screen Sharing vulnerability that hackers have been using to mine Monero on open Macs.

Apple Patches Critical macOS Flaw After Hackers Exploit Macs to Mine Monero

An updated warning by the Netherlands’ National Cyber Security Centre said Apple patched a macOS Screen Sharing vulnerability attackers exploited to gain root access and install Monero mining software on exposed Macs connected to the Internet.

On August 12, the Dutch National Cyber Security Centre reported that it had observed CVE-2026-65400 in use, targeting multiple systems connected to the internet through port 5900. In every instance it had seen, the attacker would have had root access and subsequently installed a Monero miner. The NCSC did not say how many devices were affected by the activity, nor did it name a group.

On August 6, Apple released an update for macOS Tahoe, Sequoia, and Sonoma to address the flaw. The Screen Sharing flaw is a state management error that could allow a network-based attacker to bypass authentication via the service.

Security company Huntress reported that a flaw in the SCRAM (Secure Remote Password) authentication mechanism could allow an unauthenticated connection to be treated as an authenticated connection, allowing for a privilege escalation. As the flaw occurs prior to normal authentication, changing passwords or disabling accounts does not reduce the vulnerability.

Huntress suggested applying Apple’s security updates or disabling Screen Sharing until vulnerable hosts can be updated. Researcher Ryan Dowd did a search on Censys and found tens of thousands of exposed hosts, although this number does not represent the number of infected hosts.

Read More: Zcash Is Making a Comeback: Why ZEC Could Lead Crypto’s Privacy Revival

Hosted bare-metal Macs are especially at risk, as remote Mac provisioning may leave Screen Sharing enabled on freshly provisioned machines. The vulnerability was given a CVSS severity score of 9.8 by CISA. No privileges or user interaction are required to exploit.

According to the Dutch NCSC, in these attacks, the attackers compromised these Macs to use their processing power to mine Monero (rather than stealing wallets). Once the attackers had root access to the compromised Macs, they used the Macs’ processing power to mine Monero. These addresses have not been reported: the miner and mining-pool address, the attackers’ wallets, or the amount of XMR$507.83 mined.

Read More: How Digital Platforms are Redefining Trust in Online Finance

Monero’s popularity for cryptojacking, due to its mineability on general purpose hardware, has resulted in it being frequently abused in this manner. It is part of a broader trend of cryptocurrency attacks on macOS, including both crypto-jacking and malware targeting cryptocurrency companies.

At the time of this writing, XMR traded around $417 and appreciated by around 2% against the dollar in 24 hours. Over seven days, XMR appreciated by nearly 6.7%, not reflecting the mining campaign’s size or returns.

Monero (XMR) 24-hour price chart showing a recovery from below $408 to above $418, with strong upward momentum and intraday volatility.

Security vendor Huntress noted that the best mitigation for this vulnerability is to patch vulnerable Mac systems, especially ones exposing the Screen Sharing ports directly to the Internet, even if administrators believe it is disabled. 

As the campaign is not yet proved, and there are no published public indicators of compromise for the mining infrastructure, later incident response may show how long CVE-2026-65400 was active before the patch was released.

Yevheny Serhiienko

Crypto writer living between common sense and volatility. Convinced that Bitcoin survives everything, Ethereum is always “almost ready,” and a bear market is just the market testing your resilience. Seen…