Attackers Exploit macOS Screen Sharing Flaw to Gain Root and Mine Monero

The Netherlands National Cyber Security Centrum has warned that a bug in Apple’s macOS screen sharing function is now being actively exploited. Systems with port 5900 open to the internet were compromised, with attackers obtaining root control and planting Monero cryptocurrency mining software.

The Netherlands National Cyber Security Centrum has warned that a bug in Apple’s macOS screen sharing function is now being actively exploited. The agency said systems that had port 5900 open to the internet were compromised, with attackers obtaining root control and planting Monero cryptocurrency mining software.

“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” the organisation stated. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

The flaw, CVE-2026-65400, carries a severity score of 7.1 out of 10. Apple shipped a patch last week for macOS Tahoe, Sequoia, and Sonoma. The weakness lives in the screen sharing capability that lets a remote user view the display and operate the keyboard and mouse while the Mac is on. According to the disclosure, the root cause is a defect in state management, which tracks prior events, user interactions, variables, and other system conditions.

Details of CVE-2026-65400 became public at last week’s Black Hat security conference, and a video of the exploit in action is available online. Apple’s advisory from last week said the vulnerability “may” allow an attacker without credentials to gain access to a Mac. The reason for that cautious wording is unclear, although softened language is common in vulnerability disclosures from technology vendors.

The NCSC emphasised that exploitation is happening when port 5900 is exposed to the internet. Turning on screen sharing in macOS causes the firewall to open that port. Most routers and dedicated firewalls block it unless a user or administrator deliberately changes the setting. Security professionals usually advise Mac owners to keep port 5900 closed even while using screen sharing, suggesting connections through a VPN or SSH tunnel instead. Those alternatives often demand steps that are beyond what many typical users can manage.

The simplest protective measure is to leave screen sharing switched off, enable it only when a session is needed, and disable it immediately after. The toggle is located in System Settings, then General, then Sharing, under Screen Sharing. Installing last week’s Apple security update is also essential.

So far, the observed attacks appear limited to installing Monero miners, which quietly consume a computer’s processing power to generate cryptocurrency for the attacker. A larger concern is that the same flaw could be used to deliver malware that steals login credentials or carries out other harmful actions.

Applying the macOS update and keeping screen sharing disabled unless actively needed remain the key steps, as the same vulnerability could later be used for credential theft or other malware.

Leave a Reply

Your email address will not be published. Required fields are marked *