VYPR
researchPublished Aug 15, 2026· Updated Aug 17, 2026· 2 sources

macOS Screen Sharing Vulnerability Actively Exploited for Cryptomining

A critical authentication flaw in macOS Screen Sharing, CVE-2026-65400, is being actively exploited by threat actors to gain root access and deploy Monero cryptocurrency miners.

Threat actors have begun actively exploiting a recently patched vulnerability in macOS's Screen Sharing feature, leveraging it to gain root access on compromised systems and deploy cryptocurrency miners. The vulnerability, identified as CVE-2026-65400, is a high-severity authentication bypass that allows remote attackers to log in without valid credentials.

Apple addressed this flaw on August 6th with updates for macOS Tahoe, Sequoia, and Sonoma. However, the Dutch National Cyber Security Centre (NCSC) issued a warning approximately a week later, noting that in-the-wild exploitation had commenced, likely spurred by the availability of a public proof-of-concept (PoC) exploit. The NCSC specifically highlighted that active abuse was observed on systems with port 5900 accessible from the internet.

Once attackers gain root access through this vulnerability, they are deploying Monero cryptocurrency miners. This indicates a financially motivated objective behind the attacks, aiming to utilize the victim's computing resources for illicit mining operations. The ease of exploitation, requiring only the knowledge of an account name, makes it a particularly attractive target for malicious actors.

According to security firm Calif, the vulnerability requires an attacker to simply name an existing account on the target macOS system. Since usernames are often visible on the login window, this presents a minimal barrier to entry. This ease of access, combined with the potential for significant financial gain through cryptomining, underscores the urgency for users to apply the provided patches.

CVE-2026-65400 is not an isolated incident; it follows a series of other vulnerabilities patched in the screensharingd daemon responsible for managing Screen Sharing connections. In late July, Apple had already patched at least four other issues in this component, including one that allowed unauthenticated attackers to achieve remote code execution as root.

Security researcher osxreverser had previously warned that an estimated 40,000 internet-accessible macOS systems were potentially exposed to attacks due to Screen Sharing being enabled. The now-exploited CVE-2026-65400 exacerbates this risk, as it allows for unauthorized authentication and subsequent deployment of malicious payloads like cryptominers.

The implications of this exploitation are significant, potentially leading to system performance degradation, increased electricity costs, and the compromise of sensitive data if attackers choose to pivot to other malicious activities. The ongoing exploitation of such vulnerabilities highlights the persistent threat landscape for macOS users and the critical importance of timely patching and network security monitoring.

Users are strongly advised to update their macOS systems to the latest available versions to mitigate the risk posed by CVE-2026-65400 and other recently disclosed vulnerabilities. Disabling Screen Sharing on internet-facing systems or restricting access to trusted networks can also serve as effective mitigation strategies.

Further details have emerged regarding the exploitation of CVE-2026-65400, with researchers indicating that a pre-authentication vulnerability in the Screen Sharing daemon ('screensharingd') allows attackers to compromise Macs without needing credentials. This pre-authentication flaw, distinct from the post-authentication issue initially highlighted, requires only the IP address of an internet-exposed Mac with Screen Sharing enabled. Researchers estimate around 40,000 such hosts were exposed online, with a significant portion in the U.S., including academic and corporate networks.

Synthesized by Vypr AI