macOS vulnerability exploited for takeover and crypto mining
- Thảo Nguyên

- 2 minutes ago
- 2 min read
A new security vulnerability in the macOS Screen Sharing feature is being actively exploited by malicious actors to gain control of devices and install cryptocurrency mining software.
Critical authentication flaw in screen sharing
Tracked as CVE-2026-65400, this security issue originates from the macOS Screen Sharing feature. The vulnerability allows remote attackers to log into the system without requiring a standard password. According to cybersecurity firm Calif, hackers only need to know the exact account username to breach the system - information that is not inherently secret and is often displayed directly on the Mac login screen.
To resolve this issue, Apple released patches on August 6 for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 to tighten authentication checks and block unauthorized access.
Surge in attacks following exploit release
Approximately one week after Apple announced the patches, the National Cyber Security Centre (NCSC) of the Netherlands warned of an escalating wave of real-world attacks. This heightened risk emerged following the public disclosure of Proof-of-Concept (PoC) exploit code online.
The NCSC reported that systems exposing port 5900 to the internet are the most frequently scanned targets. Upon successfully exploiting the flaw, attackers gain highest administrative privileges (root access) on the system and proceed to install hidden software to mine Monero cryptocurrency.
Chain of risks surrounding connection management process
CVE-2026-65400 is not an isolated case. Earlier in late July, Apple addressed at least four other vulnerabilities related to screensharingd - the background process responsible for handling Screen Sharing connections. Notably, one critical flaw allowed attackers to perform remote code execution with root privileges without requiring any user interaction.
According to security researcher osxreverser, this flaw can be exploited to plant a reverse shell and automatically execute hidden background tasks (crontab) with root privileges. Attackers simply need the IP address of a target device with Screen Sharing enabled and System Integrity Protection (SIP) turned off. Notably, the researcher warned on August 8 that around 40,000 internet-exposed macOS systems face an exceptionally high risk of compromise.
macOS users are urged to promptly check and update their devices to the latest operating system version to mitigate these security threats.












Comments