Attackers Exploit macOS Screen Sharing Flaw to Deploy Cryptominer
Attackers are leveraging a recently addressed security vulnerability in Apple macOS to bypass authentication mechanisms, achieve root access, and deploy a cryptocurrency mining payload, according to warnings from the Netherlands’ National Cyber Security Centre (NCSC).
Vulnerability Details
The flaw, designated CVE-2026-65400, allowed unauthorized users to connect to macOS Screen Sharing services without valid credentials. Apple resolved the issue through updates for macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1), urging users to apply the patches promptly. The company attributed the fix to enhanced state management protocols and acknowledged researcher Alfredo Pesoli, affiliated with Bynario Atlas, for disclosing the vulnerability.
Timeline of Events
On August 7, the NCSC issued an initial advisory cautioning organizations about the potential risk, though no active exploitation had been confirmed at that time. The situation escalated five days later when the agency escalated its warning following the release of proof-of-concept code and reports of ongoing attacks targeting systems with port 5900 exposed to the internet. The NCSC documented instances where attackers gained root privileges and installed a Monero cryptocurrency miner on affected devices.
User Recommendations
Users unable to apply updates immediately are advised to manually disable Screen Sharing via System Settings by navigating to General > Sharing and toggling the feature off.
Advisory
The NCSC has not disclosed specifics about the scale of the attacks, including the timeline of incidents, the number of compromised systems, or whether additional malicious activities beyond cryptocurrency mining occurred. The advisory highlights the urgency of applying security patches and securing network-facing services to mitigate risks associated with exploited vulnerabilities. Organizations are encouraged to review their configurations and monitor for signs of unauthorized access or unusual system behavior.
according to warnings from the Netherlands’ National Cyber Security Centre (NCSC).
