Particle.news

Patched macOS Screen Sharing Bug Is Being Used to Root Macs and Mine Monero

Public proof‑of‑concept code and reports of internet‑exposed Macs being rooted mean organizations must patch or cut off Screen Sharing immediately.

Overview

  • Apple released an out‑of‑band fix for CVE‑2026‑65400 on August 6 that corrected improper state management in the Screen Sharing authentication flow.
  • The Netherlands’ NCSC updated its advisory on August 12 to report active exploitation where attackers gained root on internet‑reachable Macs and installed Monero miners.
  • CISA raised the vulnerability’s score to 9.8 and labeled the flaw automatable after public proof‑of‑concept code and rapid weaponization were observed.
  • Practical risk requires Screen Sharing to be enabled and port 5900 reachable from the internet so hosted or port‑forwarded Macs are at highest exposure.
  • The only reliable defenses are installing Apple’s security updates or disabling Screen Sharing and blocking TCP/5900 until systems are patched because password resets do not stop this pre‑authentication bypass.