CVE-2026-65400: macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

CVE-2026-65400 macOS Screen Sharing vulnerability Monero miner root access exploit

Attackers have begun exploiting a critical vulnerability in macOS’s built-in Screen Sharing feature to gain access to Mac computers without any valid credentials whatsoever. In several confirmed cases, attackers who established this unauthorized connection subsequently obtained root privileges and installed a Monero cryptocurrency miner.

An Authentication Bypass in Screen Sharing

The vulnerability, tracked as CVE-2026-65400, affects the Screen Sharing feature. According to Apple’s official security advisory, a flaw in the authentication verification mechanism allowed a network-based attacker to bypass authorization entirely, without possessing valid credentials. Apple attributed the issue to improper state handling during the user verification process.

Apple patched CVE-2026-65400, rated 9.8 Critical, on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Earlier versions within each of these respective system branches remain vulnerable. According to the National Vulnerability Database (NVD), CISA’s assessment rates the potential impact on system confidentiality, integrity, and availability as maximal.

Active Exploitation Confirmed Within Days

Just days after the patch shipped, real-world attacks were confirmed. The Netherlands’ National Cyber Security Centre (NCSC) reported in an official advisory that CVE-2026-65400 was already being exploited against several computers with port 5900 directly exposed to the internet.

In every case documented by the agency, attackers gained root privileges on the compromised Macs and subsequently deployed a Monero miner. The NCSC has not disclosed the total number of affected devices, the identities of the owners, or the method attackers used to locate potential targets.

Public Exploit Code Escalates the Threat

By August 12, the situation intensified further with the emergence of publicly available proof-of-concept exploit code. The NCSC updated its advisory to highlight two critical developments: the exploit code had become public, and the vulnerability was already under active exploitation in the wild.

No User Interaction Required

CVE-2026-65400 requires no action whatsoever from the Mac’s owner – no file needs to be opened, no link clicked, and no connection manually approved. Based on current NVD data, the vulnerability can be exploited remotely over the network without any prior privileges or user interaction of any kind.

Recommended Actions

macOS users are strongly advised to install Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9, or a more recent version of the operating system. Particular attention should be paid to any Mac with Screen Sharing enabled and port 5900 exposed directly to the internet, since that exact configuration was present in every confirmed case the NCSC documented where the vulnerability was actively exploited.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply