Loading prices...
All news
Flat vector illustration of a cracked computer monitor with a glowing gold faceted coin bursting through the broken screen, symbolizing a macOS Screen Sharing exploit used to secretly mine Monero

A macOS screen-sharing bug let hackers mine Monero with root access

19:00 · 17.08.2026
Source: Decrypt
1

Leave Screen Sharing switched on and reachable from the open internet, and until eleven days ago a macOS bug was enough to hand an attacker full root access — no valid password required. Hackers used exactly that opening to quietly install Monero mining software on compromised Macs, Decrypt reported on August 17, citing an NCSC advisory from the Netherlands' National Cyber Security Center.

The flaw, tracked as CVE-2026-65400 and rated 7.1 out of 10 in severity, traces back to insufficient state management in how macOS's built-in Screen Sharing handles authentication. A faulty check let a connection be treated as successfully logged in even without valid credentials, which meant a network-based attacker could skip the login screen entirely and land with root, the highest level of system access macOS grants. Only Macs with Screen Sharing's underlying port, 5900, exposed directly to the internet are at risk — a configuration mistake rather than a default setting, but a common enough one that the Dutch NCSC documented active exploitation across multiple systems before it published anything publicly.

Apple shipped the fix — macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 — on August 6, before the NCSC's advisory went public, a normal responsible-disclosure gap that only closes once enough machines actually install the update. That gap matters here because proof-of-concept exploit code has circulated publicly since August 12, which lowers the skill this attack requires from "do the original research" to "run someone else's script." The choice of Monero over a more liquid coin isn't incidental: its default privacy features make mined proceeds far harder to trace back to a wallet, which is exactly what mining on someone else's hardware without permission needs.

There's no public count yet of how many Macs were actually compromised, and Apple has not issued its own statement beyond the patched builds themselves — the NCSC's advisory is currently the only official confirmation that exploitation happened in the wild rather than just in a researcher's lab. What is clear from the advisory is the shape of every confirmed case: root access first, a Monero miner installed second, with no other payload reported so far. That narrowness is itself informative. A root-level foothold this reliable would support far more damaging follow-on moves — credential theft, ransomware, lateral movement to other machines on the same network — and the fact that (at least so far) attackers only used it to run a miner suggests either an opportunistic, automated campaign rather than a targeted one, or simply that the more damaging use of this access hasn't surfaced publicly yet.

This isn't the first time Apple's own platforms have carried crypto-adjacent risk past the people using them: a wallet app stayed listed for a year before Apple pulled it, and the same underlying pattern — attackers treating consumer hardware and software as free infrastructure — showed up repeatedly across the security digest we ran earlier this month. Screen Sharing left open to the whole internet is an old mistake with a new payload riding on it: the vulnerability is new, but "don't expose your remote-desktop port to the entire internet" was sound advice long before anyone had heard of Monero.

Nothing here should be taken as financial advice — just information to consider.

Published: 19:00 · 17.08.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!