NewsLayer.com
NewsLayer PulseLIVEBTC$82,594-0.56%ETH$2,502-2.52%SOL$110.29-4.19%XRP$1.4-1.14%DOGE$0.085-3.75%ADA$0.2385-6.27%Total Cap$2.92T+1.11%Layer Index30 Fear

CryptoPolicy

breaking

macOS ‘Screen Sharing’ flaw exploited for crypto-mining

A feature designed to let people remotely control a Mac has become an entry point for attackers.

Bitdefender

Publisher

Aug 17, 2026 at 2:06 PM UTC · 6 min de leitura

macOS ‘Screen Sharing’ flaw exploited for crypto-mining
Image via Bitdefender
Traduzindo…

A feature designed to let people remotely control a Mac has become an entry point for attackers.

The Netherlands’ National Cyber Security Centre (NCSC-NL) says threat actors have exploited a recently patched macOS Screen Sharing vulnerability on multiple internet-accessible systems. In each reported case, the attackers obtained root-level access and installed a Monero cryptocurrency miner.

The vulnerability, tracked as CVE-2026-65400, can let a remote attacker bypass authentication and access Screen Sharing without credentials. Apple fixed the flaw on Aug. 6 in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

Key takeaways

  • CVE-2026-65400 lets attackers bypass authentication on Macs with Screen Sharing enabled
  • NCSC-NL says the flaw has been exploited against multiple systems exposing port 5900 to the internet
  • Attackers reportedly gained root access and installed Monero cryptocurrency miners
  • The vulnerability affects macOS Tahoe, Sequoia and Sonoma versions released before Aug. 6
  • Mac users should update immediately and disable Screen Sharing when it is not needed
  • A Mac that may already be compromised should be treated as fully breached, even after it is updated

What is macOS Screen Sharing?