How the Mac attack works
The vulnerability affects screensharingd, the macOS component responsible for the operating system’s built-in remote-access feature.
The flaw allows a network-based attacker to get past Screen Sharing’s normal authentication checks without valid credentials. Once access is obtained, attackers can gain root-level control of the Mac and install additional software.
NCSC-NL said that in every compromise it observed, attackers installed a Monero miner.
Security researchers at Huntress also found that common attempts to secure Screen Sharing, such as changing the password or removing authorized accounts, do not prevent exploitation of the underlying vulnerability. Patching the operating system or disabling Screen Sharing entirely is required to close the attack path.
Huntress noted that the risk is compounded by the rise of hosted bare-metal Mac services, such as cloud-based Mac minis, which often ship with Screen Sharing enabled by default. A search on the internet-scanning platform Censys turned up tens of thousands of potentially vulnerable hosts tied to such providers, according to Huntress.
Apple’s fixes cover macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Why Monero?
Monero (XMR) can be mined using general-purpose computer processors, and its privacy features can make some transactions more difficult to trace.
XMR uses a proof-of-work algorithm called RandomX, which is designed to run on general-purpose CPUs rather than the specialized mining hardware commonly used to mine Bitcoin and some other cryptocurrencies.
For attackers, this can reduce the cost of running a mining operation. They can use victims’ computing power and electricity to mine Monero rather than purchasing and operating their own hardware.
Monero also has privacy features designed to obscure the identities of parties to transactions, making some transactions more difficult to trace. Those features have drawn increased regulatory scrutiny in some jurisdictions, particularly in the context of anti-money-laundering measures.
Why This Matters
Attackers can use victims’ Macs and electricity to mine crypto, shifting the cost of the mining operation to the victim. The extra CPU usage can also slow the affected computer and increase energy consumption.
Dive into DailyCoin’s hottest crypto news today:
Trezor Warns of Phishing Risk After 14,000-Customer Data Leak
How Stablecoin Regulation Drives Blockchain Innovation 2026
DailyCoin's Vibe Check: Which way are you leaning towards after reading this article?
Never miss a market move
Get the biggest crypto stories, price insights, and DailyCoin exclusives in your inbox.