macOS Screen Sharing Flaw Exploited for Monero Mining
The Netherlands' National Cyber Security Center (NCSC) has issued a warning regarding active exploitation of a vulnerability within macOS Screen Sharing. Attackers have gained root access to systems with port 5900 exposed to the internet, subsequently installing Monero mining software. This vulnerability, identified as CVE-2026-65400, is an authentication flaw that permits network-based attackers to bypass authentication without valid credentials.
Vulnerability Details and Mitigation
Attackers utilized the highest level of control over compromised machines to deploy Monero mining programs. Monero, a privacy-focused cryptocurrency, is often favored for such operations due to its enhanced untraceability. Victims of these cryptojacking campaigns incur electricity costs and experience degraded system performance, while attackers illicitly profit from the mined cryptocurrency.
Apple has released patches to address this issue, implementing stricter validation checks in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. Users who have not updated their systems, particularly those with Screen Sharing accessible from the open internet, remain vulnerable to exploitation. The NCSC advises users to promptly apply Apple's updates and to avoid exposing Screen Sharing to the internet.
Broader Context of Cryptojacking
This campaign represents a continuation of cryptojacking activities, where unauthorized individuals leverage others' devices for cryptocurrency mining. Previous incidents have involved various methods, including malware embedded in pirated software, malicious code distributed through fake CAPTCHA pages, wallet-stealing code in mobile applications, and compromised libraries. The public proof-of-concept code for this flaw is now in circulation, potentially increasing the risk of further attacks.