Particle.news

macOS Screen Sharing Flaw Lets Attackers Gain Root and Install Monero Miners

CISA's upgrade of the bug to critical and public proof-of-concept code raise the risk that internet-exposed Macs will be weaponized until they are patched or Screen Sharing is turned off.

Overview

  • Apple issued out-of-band fixes for CVE-2026-65400 on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9, and users should install those updates immediately.
  • The NetherlandsNCSC-NL confirmed active exploitation of the Screen Sharing bug that in reported cases allowed attackers to obtain root on internet-facing Macs and install Monero miners.
  • CISA rescored the vulnerability to 9.8 on August 14 and marked it automatable, reflecting that exploits now require no privileges or user interaction to succeed.
  • Security researchers report tens of thousands of Macs with TCP port 5900 exposed to the internet, with hosted bare-metal Mac services especially at risk because providers sometimes enable Screen Sharing by default.
  • The flaw is a pre-authentication state-management bypass of the Secure Remote Password flow, so changing Screen Sharing passwords does not stop attacks and only Apple’s patch or disabling Screen Sharing fully mitigates the issue.