Particle.news

Critical macOS Screen Sharing Bug Lets Attackers Gain Root and Run Monero Miners

Proof-of-concept code with confirmed Dutch incidents increases the chance of automated mass abuse, requiring immediate patching or isolation of vulnerable Macs.

Overview

  • Apple released an out-of-band patch on Aug. 6 that fixes CVE-2026-65400 in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.
  • The Netherlands’ National Cyber Security Centre updated its advisory on Aug. 12 to say attackers exploited internet-facing Screen Sharing (TCP 5900) to obtain root on affected Macs and install Monero miners.
  • CISA re-scored the flaw to 9.8 on Aug. 14 and labeled the issue automatable, raising the likelihood of large-scale, unattended compromise now that exploit code is public.
  • The bug bypasses the Secure Remote Password flow before normal authentication, so changing Screen Sharing passwords or removing accounts does not stop the exploit; install Apple’s update or disable Screen Sharing and block TCP 5900 for externally reachable Macs.
  • Treat any confirmed root compromise as a full takeover, plan for complete remediation or reinstall, and watch hosted bare-metal Mac environments closely because they often expose Screen Sharing on newly provisioned machines.