← All articles

Exploited macOS Screen Sharing flaw gives attackers root to plant miners

The Netherlands cyber agency warned that attackers are exploiting a recently patched macOS flaw to gain root on internet-exposed Macs and install cryptocurrency miners. Tracked as CVE-2026-65400 and scored 9.8, the authentication flaw in the Screen Sharing component lets a network attacker authenticate to the built-in remote desktop service, which uses VNC on port 5900, without valid credentials due to flawed state management. Apple fixed it in emergency updates on August 6 for macOS Tahoe, Sequoia, and Sonoma. Screen Sharing is off by default, but any Mac with it enabled and reachable from the internet is at high risk, and several have already been compromised to run Monero miners.

Check
Install Apple's August macOS updates on all Macs, and confirm Screen Sharing is disabled or that port 5900 is not reachable from the internet on any system where remote desktop is enabled.
Affected
Macs with Screen Sharing enabled and reachable from the internet on unpatched macOS Tahoe, Sequoia, or Sonoma (CVE-2026-65400); a network attacker can authenticate without credentials and gain root.
Fix
Update macOS, disable Screen Sharing where it is not needed, restrict remote desktop access to trusted networks or a VPN, and check exposed Macs for unauthorized access and cryptominer processes.