Security

Hackers Exploited macOS Screen Sharing Flaw to Install Monero Miners, Dutch Cyber Agency Warns

2 min read

Attackers found an open door in Apple’s Screen Sharing feature and walked straight through it. Monero (XMR) mining software landed on internet-exposed Macs. The Netherlands’ National Cyber Security Centre (NCSC) confirmed the campaign in a published advisory.

The vulnerability carries the designation CVE-2026-65400. U.S. cybersecurity officials scored it 9.8 out of 10 on the CVSS severity scale. Apple pushed patches on Aug. 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The NCSC later updated its advisory with a key detail: the flaw had been actively exploited to deploy cryptomining malware.

Here is how the attack works. An attacker on the same network can reach a Mac through Screen Sharing without supplying a valid password. Apple ships the feature switched off by default. Hosting companies, however, routinely enable it so customers can reach “bare-metal” Apple devices rented by the hour. The exposed machines skew heavily toward remote servers rather than consumer laptops.

The vulnerability sits before authentication, according to a Huntress analysis. Changing or deleting Screen Sharing passwords offers no protection. Ryan Dowd, a researcher at Huntress, said he identified “tens of thousands of potentially vulnerable hosts” through a Censys search. Many were hourly-rented machines hosted by cloud providers.

“Anybody who leverages Apple’s Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately,” Dowd wrote.

The U.S. Cybersecurity and Infrastructure Security Agency first rated the flaw 7.1 on Aug. 6, the same day Apple shipped the fix. By Friday, that score had jumped to 9.8. The flaw has not yet landed in the federal catalog of vulnerabilities known to be under active attack.

What the NCSC left unsaid carries weight. The agency disclosed no count of compromised machines, no attribution, and no timeline for the campaign. Apple and the NCSC did not immediately respond to requests for comment from The Block.

Monero has long been the coin of choice for cryptojacking. It mines on ordinary processors, not specialized hardware. The network issues roughly 432 XMR per day. At Sunday’s price of $415.82, up about 3.7% over 24 hours per The Block’s price page, that daily emission is worth approximately $179,000. Illicit miners compete for a slice of that output using stolen compute.

The economics are quiet. A compromised server burns someone else’s electricity and racks up someone else’s bills. Monero’s privacy features make payouts difficult to trace. Holders remain divided on whether that demand is a feature or a liability.

The NCSC advisory is available at advisories.ncsc.nl. Apple’s security document detailing the patch is published on its support site.

As of the article’s publication, CISA had not added CVE-2026-65400 to its Known Exploited Vulnerabilities catalog.

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.