Apple macOS Screen Sharing Bug Exploited for Monero Mining

2–3 minutes
Fact Checked by Mazel Ventura

Last Updated:

August 17, 2026

Gold Monero coin beside a Mac showing unauthorized Monero mining activity.

Apple macOS Screen Sharing Bug Exploited for Monero Mining

Gold Monero coin beside a Mac showing unauthorized Monero mining activity.

Apple macOS Screen Sharing Bug Exploited for Monero Mining

Apple has closed a security hole in macOS Screen Sharing that let attackers take over exposed Macs and quietly install Monero mining software. The Netherlands’ National Cyber Security Centre (NCSC) reported that the bug, tracked as CVE-2026-65400, was being used against systems reachable over port 5900. In every case the agency reviewed, the outcome was the same: full root access followed by a cryptocurrency miner running in the background.

How the Screen Sharing Flaw Let Attackers In

The flaw sat inside the SCRAM authentication process that ‘Screen Sharing’ uses to verify the identity of the person connecting. According to Cyber Security News, Apple’s system handles two separate login paths differently depending on how a user connects, and that inconsistency let an unauthenticated request pass as if it had already been approved.

Security firm Huntress reported that this lets attackers skip login entirely and jump straight to root-level control, since the weakness triggers before any password check takes place. Resetting a password or locking an account would not have stopped it.

The bug carried a CVSS severity score of 9.8, and CISA noted it required no user interaction to exploit. Researcher Ryan Dowd ran a scan through Censys and turned up tens of thousands of Macs with Screen Sharing exposed to the open internet, though that count reflects exposure, not confirmed infections. Rented or hosted Mac hardware carries extra risk here, since providers sometimes leave Screen Sharing switched on by default when a machine is first provisioned.

Once inside, attackers did not go after wallets or personal files. Instead, they pointed the Mac’s own processing power at mining Monero. The NCSC has not released the mining pool address, the attackers’ wallet, or how much XMR was generated from the campaign.

What This Means for Mac Users

Anyone running a Mac with Screen Sharing turned on and reachable from the open internet, including rented or hosted machines used for remote work, should treat this as urgent. Monero remains a frequent target for this kind of quiet, background hijacking because it can still be mined profitably on ordinary consumer hardware, unlike Bitcoin.

For readers newer to how these attacks work, our guide to common crypto security mistakes covers the basic habits, like keeping software updated and closing unused remote access tools, that keep a device like this one from becoming an easy target.

What to Watch Next

Neither the NCSC nor CISA has disclosed how many Macs were compromised or who is behind the campaign. Watch for a follow-up disclosure from either agency in the coming weeks, since that number would show how far the campaign actually spread beyond the tens of thousands of exposed hosts already identified through public scans.

What this means for you: If you or your business runs a Mac with Screen Sharing enabled, whether it is your own machine or a rented server, install Apple’s latest security update today, since this bug needed nothing more than an open port to hand an attacker full control and start mining crypto on your hardware without your knowledge. 

Join our growing community

David Constantino

Author

David is a crypto enthusiast, airdrop farmer, and blog writer with a focus on discovering and analyzing new token launches and blockchain projects. He explores the latest trends, shares actionable insights, and guides readers through opportunities in the fast-paced world of digital assets.