TechNewsReel
Live

Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miners

A critical authentication bypass allows attackers to gain root access to Macs with exposed remote desktop ports.

TechNewsReel Newsroom · August 14, 2026

Attackers are actively exploiting a critical authentication bypass vulnerability in macOS Screen Sharing to hijack systems and install cryptocurrency miners. The flaw allows remote actors to bypass login requirements entirely, granting them full administrative control over affected machines.

Tracked as CVE-2026-65400, the vulnerability carries a CVSS score of 7.1. To execute the attack, hackers target systems where Screen Sharing is enabled and TCP port 5900 is exposed to the public internet. Once the authentication is bypassed, attackers gain root access to the device. According to the Netherlands' National Cyber Security Centre (NCSC), every reported victim of these attacks had their root access compromised and a Monero miner installed on their system.

The Technical Failure

macOS Screen Sharing is a built-in remote desktop feature that utilizes the VNC protocol. The vulnerability results from improper state management during the login process, which enables an attacker to skip the credential validation phase. This allows for an immediate transition to an authenticated state without providing a valid username or password. This method follows a recurring pattern in cybercrime where automated scanners identify exposed remote-access services to deploy resource-heavy software for financial gain.

Industry Implications

The ability to obtain root access without credentials represents a severe security failure. While the current wave of attacks focuses on deploying Monero miners to profit from the victim's hardware resources, the implications of root access extend far beyond cryptocurrency mining. With administrative privileges, an attacker can steal sensitive personal or corporate data, install persistent backdoors for long-term surveillance, or use the compromised Mac as a pivot point to launch further attacks within a secure corporate network. This incident underscores the significant risk of exposing administrative ports, such as port 5900, directly to the internet.

Remediation and Next Steps

Apple addressed the vulnerability on August 6, 2026, releasing security patches for several operating system versions. The updates are available for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Users are urged to update their systems immediately to close the loophole. Security professionals recommend that organizations audit their firewall configurations to ensure that Screen Sharing ports are not accessible from the public web, suggesting the use of VPNs or secure gateways for remote administration instead.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.