Breaking
SecurityDeveloping Story

Mac screen sharing flaw is being exploited to mine crypto

A high-severity macOS bug is under attack, with hackers placing Monero miners via port 5900.

··2 hours ago·3 min read
black and gray laptop computer
Photo by Roger Cai on Unsplash

Dutch cybersecurity officials have raised the alarm over a macOS vulnerability that is being actively exploited to seize control of Macs and install cryptocurrency miners. The Netherlands National Cyber Security Centrum (NCSC) reported that multiple systems with port 5900 exposed to the internet have been compromised, all with root access obtained and a Monero crypto miner placed.

Active exploitation and root access

The NCSC’s warning, issued earlier this week, states: “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet. In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed.”

This suggests attackers are already using the flaw to gain full control of vulnerable Macs, using them to mine cryptocurrency without the owner’s knowledge. The exact number of affected systems remains unspecified, but the confirmed cases point to a real and ongoing threat.

CVE-2026-65400 details

The vulnerability, formally tracked as CVE-2026-65400, carries a severity rating of 7.1 out of 10. It stems from a bug in macOS’s screen sharing capability, which allows a remote party to view the screen and control the keyboard and mouse while a machine is turned on. The underlying cause is a flaw in “state management,” which keeps track of preceding events, user interactions, variables, and other system states.

Apple released a patch last week for macOS Tahoe, Sequoia, and Sonoma. The company’s advisory described the issue with an unusual qualification, stating that CVE-2026-65400 “may” allow an attacker without credentials to gain access to a Mac. The reason for this hedging is unclear, but softer language is common among tech developers when disclosing vulnerabilities.

Details revealed at Black Hat

Technical details of CVE-2026-65400 became public last week at the Black Hat security conference, where a video of the exploit in action was also shared. The public disclosure likely accelerated exploitation, as attackers quickly adapted to the newly revealed attack vector.

Port 5900 exposure risk

The vulnerability is being exploited when port 5900 is exposed to the internet. When screen sharing is turned on, the macOS firewall opens the port. Routers and dedicated firewalls generally block the port unless configured to override that setting. However, in the observed attacks, port 5900 was accessible, indicating that the affected systems had the port open.

Security practitioners generally advise Mac users to keep the port closed even when using screen sharing and to instead connect over a VPN or through SSH tunneling. The alternatives require actions that aren’t within the capabilities of most users.

Mitigation and best practices

The safest practice is to block screen sharing, enable it only when screen sharing is needed, and to turn the feature off once a session has ended. Screen sharing can be turned on or off by accessing System Settings > General > Sharing and toggling the switch for Screen Sharing. Installing last week’s security update is also a must.

While the current exploits appear limited to installing Monero miners, the risk is that attackers could leverage the same vulnerability for more damaging purposes, such as credential theft or other nefarious activities. No such attacks have been observed yet, but the possibility remains.

Current impact and outlook

Right now, there are no indications exploits are being used to install anything other than Monero miners, which surreptitiously harness a Mac’s resources to perform mathematical operations that generate the cryptocurrency for the attacker. The mining activity is a clear sign of unauthorized access, but the broader danger is that the same flaw could be used for more serious intrusions.

As the NCSC’s warning underscores, the active exploitation of CVE-2026-65400 is a concrete threat. Mac users should take immediate steps to protect their systems, including applying the latest updates and reconsidering their screen sharing settings.

#macos#cve#vulnerability#monero#ncsc

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories