Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

Your Mac Could Be Mining Monero (XMR) for Hackers — Apple Issues Emergency Fix

Your Mac Could Be Mining Monero for Hackers — Apple Issues Emergency Fix
Your Mac Could Be Mining Monero for Hackers — Apple Issues Emergency Fix

Key Takeaways

  • Hackers are actively exploiting a macOS Screen Sharing flaw to gain root access and install Monero mining software.

  • Apple patched the vulnerability on Aug. 6, but Macs running older versions remain exposed if Screen Sharing is reachable from the internet.

  • CISA now rates the bug 9.8 out of 10, after initially assigning it a much lower severity score.

Hackers are turning vulnerable Macs into Monero mining machines by exploiting a critical flaw in Apple's built-in Screen Sharing feature.

Advertisement
Advertisement

The vulnerability, tracked as CVE-2026-65400, allows an attacker to authenticate to Screen Sharing without valid credentials. Apple released fixes on Aug. 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

Apple described the bug as an authentication problem caused by flawed state management. What initially appeared to be another macOS security patch has since become more urgent as evidence of real-world attacks has surfaced.

Hackers Are Already Using the Bug to Mine Monero (XMR)

The Netherlands' National Cyber Security Centre said on Aug. 12 that it had received reports of the vulnerability being exploited across multiple systems where port 5900, used by Screen Sharing, was exposed to the internet.

In every case reported to the agency, attackers gained root access and installed a Monero cryptocurrency miner . Public proof-of-concept code is also available, increasing the risk that more attackers could reproduce the exploit.

Advertisement
Advertisement

Root access gives an attacker extensive control over a Mac. In the attacks identified so far, that control was used for cryptojacking , where a victim's computing power is quietly redirected to mine cryptocurrency for someone else.

Security firm Huntress found that CVE-2026-65400 affects the Secure Remote Password authentication process used by Screen Sharing. A flaw in the process can cause an unauthenticated connection to be treated as authenticated, allowing malicious code to run without the attacker first logging into the machine.

Hosted Macs may be especially exposed because remote-access services such as Screen Sharing are more commonly enabled on machines used for remote workloads. Huntress said internet scans show tens of thousands of potentially exposed systems.

Apple Patch Becomes More Urgent

The vulnerability's risk rating has also climbed sharply.

Advertisement
Advertisement

CISA now assigns CVE-2026-65400 a 9.8 critical CVSS score, with the assessment showing that exploitation requires no prior privileges or user interaction and can result in major confidentiality, integrity and availability losses.

Mac users running Screen Sharing should update to Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9.

For users who cannot update immediately, disabling Screen Sharing removes the exposed service. Changing a Screen Sharing password alone is not enough because the vulnerability can be exploited before normal authentication takes place.

So far, authorities have not disclosed how many Macs have been compromised or how much Monero attackers have mined through infected machines.

Advertisement
Advertisement

Top Trending Crypto Articles

The post Your Mac Could Be Mining Monero (XMR) for Hackers — Apple Issues Emergency Fix appeared first on ccn.com .

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: