This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$62,729-0.54%ETH$1,872-0.57%SOL$74.3-1.63%XRP$0.9921-1.12%DOGE$0.0695-0.47%ADA$0.1748-1.44%Total Cap$2.26T-0.62%Layer Index42 Neutral
BreakingExternal ReportingYayınlandı 11 saat önce

Hackers exploit macOS screen sharing vulnerability to mine Monero

A remote desktop feature built into every modern Mac has become an open door for hackers, and Dutch cybersecurity officials say the break-in is already happening. Security researchers and government agencies are now warning users about…

Hackers exploit macOS screen sharing vulnerability to mine Monero
Publisher The Cryptonomist 5 dk okuma
Image via The Cryptonomist

Layer Index

42

↓ 7 pts in 24h

A remote desktop feature built into every modern Mac has become an open door for hackers, and Dutch cybersecurity officials say the break-in is already happening. Security researchers and government agencies are now warning users about an actively exploited macOS screen sharing vulnerability that lets attackers take control of a computer without ever needing a password, then quietly install cryptocurrency mining software on the machine.

Key takeaways

  • The flaw, tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10 and lets attackers execute code remotely without valid credentials.
  • The Netherlands’ National Cyber Security Centrum (NCSC) confirmed active exploitation on systems where port 5900 was reachable from the internet.
  • Attackers who exploited the bug gained root access and installed Monero crypto miners on affected Macs.
  • Apple patched the issue last week in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
  • Users can reduce risk by disabling Screen Sharing when it’s not in use and installing the latest security update.

High-Severity macOS Vulnerability Allows Remote Code Execution

CVE-2026-65400 is a bug that lets a remote attacker run malicious code on a Mac without needing a username or password. Apple’s built-in Screen Sharing feature, which uses the VNC protocol to let one computer view and control another over a network, is at the center of the problem.

Nature and Source of the Vulnerability

The root cause traces back to how macOS handles “state management” inside the screen sharing system — the internal bookkeeping that tracks prior events, user interactions, and system variables. A flaw in that logic allows an intruder to sidestep proper credential checks entirely. In practical terms, someone connecting to a vulnerable Mac’s screen sharing port doesn’t need to prove who they are before gaining access.

Severity Rating and Technical Details

Apple and security researchers rate the flaw at 7.1 out of 10, a score that lands it in high-severity territory without reaching the maximum critical tier. Details of the bug first became public at last week’s Black Hat security conference, and Apple’s own advisory described the issue cautiously, saying the vulnerability “may” allow an attacker without credentials to access a Mac. That kind of hedged language is fairly typical across the tech industry when companies disclose security flaws, even when exploitation is already confirmed in the wild.

Active Exploitation Confirmed by Dutch National Cyber Security Centrum

The NCSC says it has already received reports of real-world attacks exploiting this macOS screen sharing vulnerability, not just theoretical risk. In an advisory update, the agency stated it had received a notification indicating active abuse of the flaw on multiple systems where port 5900 was accessible from the internet.

Conditions for Exploitation

Port 5900 is the network channel that VNC-based screen sharing uses to communicate. When a Mac user turns Screen Sharing on, the built-in macOS firewall automatically opens that port. Most home routers and dedicated firewalls block port 5900 by default, but if a network has been configured to allow it through — intentionally or otherwise — the machine becomes reachable from anywhere on the internet. That exposure is exactly the condition the NCSC says attackers have been exploiting.

Observed Impact on Affected Macs

According to the NCSC’s advisory, every confirmed case followed the same pattern: attackers gained root access to the system, then placed a Monero crypto miner on the machine. Monero mining malware quietly hijacks a computer’s processing power to generate cryptocurrency for the attacker, often without any obvious symptoms beyond a sluggish machine and a spike in electricity use. So far, there’s no indication that attackers have used the exploit to deploy anything more damaging than a crypto miner — but the same root-level access could theoretically be repurposed to steal credentials or install more harmful malware.

Apple Issues Patch and Security Recommendations

Apple has already shipped a fix, which is the single most effective way to close off this attack path. The company released updates last week that improve the state management mechanisms behind Screen Sharing, enforcing proper credential validation and blocking the rogue authentication attempts that made the exploit possible.

Patch Release Details

The fix landed in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9. Anyone running an older build of these three macOS releases remains exposed to the vulnerability until they update.

User Security Best Practices

Beyond installing the patch, security practitioners recommend keeping Screen Sharing off unless it’s actively needed, and switching it off again once a session ends. The toggle sits in System Settings, under General, then Sharing, where users can switch the Screen Sharing option on or off. For those who need remote access, connecting through a VPN or SSH tunnel instead of exposing port 5900 directly to the internet is considered safer, though that approach requires technical steps that fall outside what most everyday users are equipped to configure. That gap is part of why an addressable macOS screen sharing vulnerability like this one still manages to catch so many systems off guard: the safest workaround demands more networking know-how than the average Mac owner has on hand.

Why This Still Matters for Mac Users

This case is a reminder that convenience features carry hidden exposure. Screen Sharing is meant to make remote troubleshooting and file access easier, but leaving it switched on by default — especially on a network where port 5900 slips past a router’s firewall — turns a helpful tool into an open invitation. The NCSC hasn’t disclosed how many systems have been hit, when the attacks began, or whether the exploitation extends beyond cryptomining, leaving open the possibility that some compromised Macs are dealing with more than just a hidden miner running in the background.

FAQ

What is the nature of the macOS vulnerability CVE-2026-65400?

It is a flaw in macOS screen sharing state management that allows remote attackers to execute malicious code without credentials.

How are attackers exploiting this vulnerability?

Attackers exploit the vulnerability when port 5900 is exposed to the internet and screen sharing is enabled, gaining root access and installing Monero miners.

Which macOS versions have a patch for this vulnerability?

Apple released patches last week for macOS Tahoe, Sequoia, and Sonoma to fix the vulnerability.

What security steps can users take to protect themselves?

Users should disable screen sharing when not in use, close port 5900, and install the latest security updates.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Son Dakika

Hiçbir son dakika haberini kaçırmayın

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by The Cryptonomist

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

İlgili Haberler