TechNewsReel
Live

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

A critical authentication bypass allows remote attackers to gain root access to internet-exposed Macs.

TechNewsReel Newsroom · August 17, 2026

A critical authentication bypass vulnerability in macOS Screen Sharing is being actively exploited in the wild to hijack Mac computers. The flaw, tracked as CVE-2026-65400, allows remote attackers to bypass security protocols and gain unauthorized root access to affected systems without requiring any user credentials or interaction.

According to security reports from Malwarebytes and other industry sources, threat actors are leveraging this vulnerability to install Monero cryptocurrency miners on compromised machines. The exploit specifically targets macOS devices that have the Screen Sharing feature enabled and are exposed to the network, typically via port 5900. Once the authentication is bypassed, the attacker gains full administrative control over the system, enabling the silent installation of malware.

The Technical Gap

Screen Sharing is a native macOS utility designed to let users remotely control their computers via System Settings. However, CVE-2026-65400 stems from improper state management within the service. This logic error allows an attacker to trick the system into granting access without a valid password. While the vulnerability is severe, it requires the target device to have the sharing feature active and be reachable over the internet or a local network.

Industry Implications

This flaw is considered high-severity because it provides the highest level of system privilege—root access—with minimal effort from the attacker. The speed of the attack cycle is particularly concerning; active exploitation began within a week of the vulnerability becoming known. This rapid weaponization underscores a growing trend where threat actors monitor patch releases to identify and exploit unpatched systems before administrators can apply updates.

Remediation and Outlook

Apple released a formal patch to address the vulnerability on August 6, 2026. Security experts urge all macOS users to update their operating systems immediately to close the security hole. For those unable to update instantly, disabling Screen Sharing in System Settings > General > Sharing or blocking port 5900 at the firewall level can mitigate the risk. Security researchers continue to monitor for further variants of the exploit or shifts in the types of malware being deployed through this vector.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.