Apple has released emergency security updates to address a critical vulnerability in the macOS Screen Sharing component that threat actors have actively exploited to hijack devices. The flaw, tracked as CVE-2026-65400, allowed unauthorized individuals to bypass authentication protocols and gain control over systems exposed to the internet. According to reports from cybersecurity agencies, attackers utilized this access to deploy Monero (XMR) mining software, turning compromised hardware into unauthorized nodes for cryptocurrency generation.
Exploitation of CVE-2026-65400 and Cryptojacking
The Dutch National Cyber Security Centre (NCSC) issued a warning noting that the vulnerability carries a CVSS score of 9.8, classifying it as a critical threat. The exploit targets systems with port 5900 open, enabling attackers to bypass credential requirements through flaws in state management. Once access is secured, attackers have been observed escalating privileges to root level to install persistent mining scripts.
- Targeted Port: TCP 5900 (Default for Screen Sharing/VNC).
- Primary Objective: Deployment of XMRig or similar Monero miners.
- Impact: Significant degradation of hardware performance and increased electricity costs for victims.
Cryptojacking remains a preferred method for cybercriminals due to the privacy-centric nature of Monero, which makes tracking the movement of illicitly mined funds challenging for authorities.
Security Response and Affected Versions
In response to the active exploitation, Apple deployed patches on August 6, 2026, to strengthen credential validation. Security researcher @osxreverser also identified additional pre-authentication weaknesses in the same component, highlighting the necessity of immediate software updates for all users operating within the Apple ecosystem.
The following versions contain the necessary security fixes:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
The vulnerability allowed attackers to access Macs exposed to the internet without valid credentials and deploy Monero mining software, the NCSC confirmed in their technical briefing.
To mitigate the risk of unauthorized cryptocurrency mining and data breaches, administrators are advised to disable Screen Sharing if not required or restrict access via a VPN. Users should verify their current macOS version and apply the August 6th updates immediately to protect their hardware assets from being co-opted into malicious mining botnets.
Frequently Asked Questions
Quick answers to the most common questions about this topic.