Apple ships emergency patch for macOS Screen Sharing flaw exploited to install Monero miners
Apple has shipped emergency patches for a critical macOS Screen Sharing flaw that attackers are actively exploiting to take over internet-exposed Macs and mine Monero. The Dutch National Cyber Security Centre (NCSC-NL) said on August 12 that every attack it had logged followed the same path: the intruder gained root-level control of the machine, then installed a Monero cryptocurrency miner.
Tracked as CVE-2026-65400, the flaw allows an unauthenticated remote attacker to access the built-in remote-desktop service. The root cause is improper state management: Screen Sharing can lose track of whether a connection has already been authenticated, so an unauthenticated visitor is treated like a trusted one. Roughly 40,000 systems are reachable through port 5900, the port the service listens on.
What the macOS Screen Sharing flaw means
Apple shipped the fix out-of-band on August 6. It covers three macOS versions: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, with credential validation now enforced through improved state handling. Changing or resetting the Screen Sharing password will not close the hole; only the security update will. CISA followed on August 14, raising the CVSS score from 7.1 to 9.8, reversing its earlier position that the attack could not be automated and noting that the flaw requires no privileges and no user interaction.
The higher rating fits what NCSC-NL observed in real attacks, where the miner went in only after root access was secured. Technical details of the bug were presented at Black Hat. The Monero payload is a secondary concern: the same root-level access could be repurposed for data theft or ransomware.
What to do now
Install the patch on every Mac running macOS Tahoe, Sequoia or Sonoma as soon as possible. The macOS Screen Sharing flaw is confirmed in the wild and requires no credentials, so there is little reason to delay. If Screen Sharing is not needed from outside the local network, disable it or block port 5900 at the router or firewall.
Why this matters
For Mac owners, this is a patch-now situation: a password change cannot close the hole, and attackers are actively scanning for exposed systems. Any remote-access service opened to the internet becomes a target, so keeping Screen Sharing off or firewalled is the cheapest protection available.
Related Articles
- Apple's iOS 26.5.2 Security Update Patches 29 Vulnerabilities as AI Threats Accelerate
- OpenAI Security Update macOS: Urgent Patch Issued After Supply-Chain Attack
- Apple Ships Critical iOS 26.6 Security Update While iOS 27 Beta 2 Opens Siri AI Early Access
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.