All stories
Big Tech

Critical macOS Screen Sharing Flaw Actively Exploited for Remote Root Access and Monero Cryptojacking

A severe authentication bypass vulnerability in macOS Screen Sharing, rated 9.8 by CISA, is under active exploitation, granting attackers remote root access to unpatched Macs for cryptocurrency mining.

By TECH NEWS Editorial·Source:Tom's Hardware·4 min read·just now

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Critical macOS Screen Sharing Flaw Actively Exploited for Remote Root Access and Monero Cryptojacking

A critical authentication bypass vulnerability, identified as CVE-2026-65400, in macOS Screen Sharing is currently under active exploitation, allowing attackers to gain remote root access to unpatched Macs and deploy Monero cryptojackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) initially rated the bug at a CVSS score of 7.1 but subsequently elevated it to a critical 9.8 on August 14, 2026, after assessing that no privileges are required for exploitation and a full compromise of confidentiality, integrity, and availability is possible. This significant re-rating underscores the extreme severity of the flaw, which the Dutch National Cyber Security Centre (NCSC-NL) reported on August 12, 2026, is being actively abused in the wild.

The core of CVE-2026-65400 lies in an authentication issue within the macOS Screen Sharing service, which operates on TCP port 5900. Apple's official advisory, released on August 6, 2026, describes the vulnerability as an authentication problem addressed through "improved state management". This flaw allows an attacker on the network to bypass standard authentication mechanisms and gain unauthorized access without needing valid credentials. Security researchers have demonstrated that exploitation can extend beyond simply viewing a user's screen, potentially leading to substantial, even root-level, control of the affected Mac. The attack vector requires no user interaction and is described as having low attack complexity, making it highly exploitable. Public proof-of-concept code became available shortly after Apple's patch, accelerating active exploitation.

The immediate impact on users and the industry is profound. For individual users, an unpatched Mac with Screen Sharing enabled and port 5900 exposed to the internet is vulnerable to complete system compromise. Attackers are primarily leveraging this vulnerability to install Monero cryptocurrency miners, leading to sustained high CPU usage and degraded system performance, often disguised as legitimate macOS processes. While cryptojacking might seem less destructive than data theft or ransomware, it drains system resources, increases energy consumption, and can mask more insidious backdoors for future attacks. For organizations, particularly those utilizing Macs for remote administration, development, or in shared environments, the risk is amplified. The ability to gain root access without credentials on networked machines represents a critical entry point into corporate networks, potentially leading to lateral movement and broader data breaches. Enterprises managing large fleets of Macs face a significant challenge in ensuring all systems are patched promptly, especially since older, unsupported macOS versions do not receive this fix, necessitating upgrades to supported releases like macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9. Disabling Screen Sharing via System Settings is a recommended immediate mitigation for unpatched systems.

This vulnerability highlights a persistent challenge for macOS security, often perceived as inherently more secure than Windows due to its smaller market share and Unix-based architecture. However, this perception is increasingly becoming a "myth," as Macs have become more attractive targets for cybercriminals, with the volume of threats per Mac growing at double the rate of Windows PCs threats as of 2020. While Apple has made strides in built-in security features like Gatekeeper, SIP, and sandboxing, and has moved towards continuous, automatic security updates, critical flaws still emerge. This CVE-2026-65400 is particularly concerning because it represents a pre-authentication remote code execution vulnerability, a class of bugs that are highly prized by attackers as they require no prior access or user interaction. This contrasts with another Screen Sharing bug, CVE-2026-43760, patched just weeks prior, which still required valid credentials for exploitation. The ease of exploitation for CVE-2026-65400, described as requiring only "one or two packets in the right order" to gain access, underscores its severity and broad applicability. Historically, macOS has faced similar high-profile authentication bypasses, such as the "root" vulnerability in High Sierra (2017), which also allowed local or remote root access without a password, demonstrating a recurring pattern of critical flaws in core system services.

Looking ahead, the active exploitation of CVE-2026-65400 will likely drive an increased focus on network-facing services in macOS and prompt a more proactive approach to endpoint security in Mac environments. Organizations must move beyond the assumption that Apple's built-in defenses are sufficient, especially as Macs constitute a growing share of enterprise endpoints. This incident reinforces the need for robust patch management, network segmentation, strict access controls, and real-time endpoint protection that specifically targets Mac-specific threats, including zero-days. The rapid re-scoring by CISA and the NCSC-NL's urgent warnings indicate that security agencies are increasingly prioritizing immediate action for actively exploited vulnerabilities, irrespective of the operating system. Apple, in turn, will face continued pressure to enhance the security posture of its core services, potentially through more rigorous internal auditing and bug bounty programs focused on pre-authentication flaws. The increasing sophistication of malware, often written in cross-platform languages, means that "security by obscurity" is definitively dead for macOS. The industry will continue to see a shift towards comprehensive, multi-layered security strategies for Macs, treating them with the same scrutiny as any other critical infrastructure component.