Attackers are exploiting a critical macOS Screen Sharing vulnerability to gain root access and install Monero miners on internet-exposed Macs.
Attackers are exploiting a critical macOS Screen Sharing vulnerability to gain root access and install Monero miners on internet-exposed Macs.

Attackers exploited a critical macOS Screen Sharing vulnerability, rated 9.8 on the CVSS scale, to gain root access and install Monero miners on internet-exposed Macs, the Netherlands' National Cyber Security Centre said.
"In all these cases, root had gained access to the affected system and placed a Monero crypto miner," the agency said in an advisory, citing reports of abuse across multiple systems where port 5900 was reachable from the public internet.
The flaw, tracked as CVE-2026-65400, stems from improper state management in the Screen Sharing authentication process, letting an attacker on the network authenticate without valid credentials. Apple released emergency fixes Aug. 6 for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9, crediting security researcher Alfredo Pesoli of Bynario for the discovery. The U.S. Cybersecurity and Infrastructure Security Agency revised the CVSS vector Aug. 14 to reflect a remotely exploitable flaw requiring no privileges or user interaction, lifting the score from an earlier 7.1.
The confirmed attacks so far have focused on cryptocurrency mining, but the same entry point could enable credential theft, data exfiltration or ransomware. A researcher who goes by @osxreverser said a scan found roughly 40,000 internet-accessible Screen Sharing hosts, nearly half in the U.S., a measure of the reachable attack surface for enterprises running remotely managed Macs, build servers and development infrastructure.
The vulnerability sits in the Screen Sharing daemon, screensharingd, which handles incoming connections over the Remote Framebuffer protocol on TCP port 5900. Researchers described the weakness as a state-machine desync: by sending specially ordered packets, an attacker can make the service advance as though an authentication step had succeeded without supplying credentials. Some exploitation paths require knowing a local account name, which offers little protection because usernames are often visible on the login screen.
Huntress said its analysis showed the flaw affects the service's implementation of the Secure Remote Password protocol and can result in pre-authentication remote code execution. All earlier builds in the three supported macOS branches remain vulnerable, including Tahoe 26.6, Sequoia 15.7.8 and Sonoma 14.8.8.
CVE-2026-65400 is distinct from a separate pre-authentication bug fixed in macOS Tahoe 26.6, which shipped late last month alongside three other Screen Sharing flaws: CVE-2026-43779 (CVSS 9.8), a logic issue letting an app intercept network connections; CVE-2026-43777 (7.5), a denial-of-service flaw; and CVE-2026-43760 (8.6), an access issue exposing user-sensitive data. Calif, an AI security firm, said it reconstructed a working exploit for both pre-auth flaws in about four hours by comparing patched and unpatched binaries, and is withholding technical specifics until most users upgrade.
For enterprises, the disclosure shows how quickly reliable exploit code can be weaponized once a vendor ships a patch. Organizations running unpatched Macs with port 5900 exposed should treat the issue as an immediate patching priority, disable Screen Sharing when unused, and investigate any system that was both vulnerable and reachable. A patch does not remove malware already placed, so affected machines may require isolation and rebuild.
This article is for informational purposes only and does not constitute investment advice.