top of page

macOS vulnerability exploited for takeover and crypto mining

A new security vulnerability in the macOS Screen Sharing feature is being actively exploited by malicious actors to gain control of devices and install cryptocurrency mining software.

Critical authentication flaw in screen sharing

Tracked as CVE-2026-65400, this security issue originates from the macOS Screen Sharing feature. The vulnerability allows remote attackers to log into the system without requiring a standard password. According to cybersecurity firm Calif, hackers only need to know the exact account username to breach the system - information that is not inherently secret and is often displayed directly on the Mac login screen.

To resolve this issue, Apple released patches on August 6 for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 to tighten authentication checks and block unauthorized access.

Surge in attacks following exploit release

Approximately one week after Apple announced the patches, the National Cyber Security Centre (NCSC) of the Netherlands warned of an escalating wave of real-world attacks. This heightened risk emerged following the public disclosure of Proof-of-Concept (PoC) exploit code online.

The NCSC reported that systems exposing port 5900 to the internet are the most frequently scanned targets. Upon successfully exploiting the flaw, attackers gain highest administrative privileges (root access) on the system and proceed to install hidden software to mine Monero cryptocurrency.

Chain of risks surrounding connection management process

CVE-2026-65400 is not an isolated case. Earlier in late July, Apple addressed at least four other vulnerabilities related to screensharingd - the background process responsible for handling Screen Sharing connections. Notably, one critical flaw allowed attackers to perform remote code execution with root privileges without requiring any user interaction.

According to security researcher osxreverser, this flaw can be exploited to plant a reverse shell and automatically execute hidden background tasks (crontab) with root privileges. Attackers simply need the IP address of a target device with Screen Sharing enabled and System Integrity Protection (SIP) turned off. Notably, the researcher warned on August 8 that around 40,000 internet-exposed macOS systems face an exceptionally high risk of compromise.

macOS users are urged to promptly check and update their devices to the latest operating system version to mitigate these security threats.

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page