Monday, 17 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves

TechRadar ·
MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves

CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately Less than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.

Alfredo Pesoli, a security researcher from Bynario, discovered an authentication issue in macOS Screen Sharing and reported it to Apple.

Screen Sharing is a built-in macOS tool that allows users to remotely connect, and use, another Mac device.

It is similar to third-party tools such as AnyDesk or TeamViewer and comes in rather handy for IT teams accessing Macs stored in closets or used by remote and home-working employees.

The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials.

It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.

The Netherlands issue a warning Soon after disclosure, Apple released an out-of-bound fix, signaling that this is, indeed, a dangerous vulnerability.

“Apple does not ship an update out of band unless something is critical,” security researchers Calif said in their technical writeup .

The National Vulnerability Database (NVD) assigned it an identifier - CVE-2026-65400 - and gave it a severity rating of 9.6/10 (critical).

Approximately at the same time the patch was released, the flaw was also showcased at the 2026 Black Hat conference, with a video demonstration was made public a few days later.

Apple said it fixed it with improved state management, addressing the bug in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1.

Now, less than a week after the disclosure, researchers are saying the bug is being leveraged in actual cyberattacks, with Dutch security officials being first to react “The NCSC has received a report showing that active abuse of this vulnerability has been observed on several systems on which port 5900 was accessible from the internet,” the Netherlands National Cyber Security Centrum (NCSC) said in a machine-translated report.

“In all these cases, root access was gained on the affected system and a Monero crypto miner was placed.” Why Monero? Monero is considered an “altcoin” - a cryptocurrency built as an alternative to Bitcoin.

It is one of the oldest active altcoins out there, having been launched more than 12 years ago.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›