A feature designed to let people remotely control a Mac has become an entry point for attackers.
macOS ‘Screen Sharing’ flaw exploited for crypto-mining
A feature designed to let people remotely control a Mac has become an entry point for attackers.
Bitdefender
Publisher
Aug 17, 2026 at 2:06 PM UTC · 6 Min. Lesezeit

The Netherlands’ National Cyber Security Centre (NCSC-NL) says threat actors have exploited a recently patched macOS Screen Sharing vulnerability on multiple internet-accessible systems. In each reported case, the attackers obtained root-level access and installed a Monero cryptocurrency miner.
The vulnerability, tracked as CVE-2026-65400, can let a remote attacker bypass authentication and access Screen Sharing without credentials. Apple fixed the flaw on Aug. 6 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Key takeaways
- CVE-2026-65400 lets attackers bypass authentication on Macs with Screen Sharing enabled
- NCSC-NL says the flaw has been exploited against multiple systems exposing port 5900 to the internet
- Attackers reportedly gained root access and installed Monero cryptocurrency miners
- The vulnerability affects macOS Tahoe, Sequoia and Sonoma versions released before Aug. 6
- Mac users should update immediately and disable Screen Sharing when it is not needed
- A Mac that may already be compromised should be treated as fully breached, even after it is updated
What is macOS Screen Sharing?
Article Intelligence
Topics
Related Coverage
View all relatedSponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
