Mac Users Face Monero Mining Threat From Newly Found Flaw
- Attackers are actively exploiting a macOS Screen Sharing flaw tracked as CVE-2026-65400.
- The exploit targets systems with port 5900 directly exposed to the internet.
- Apple released emergency security patches across macOS Tahoe, Sequoia, and Sonoma.
A critical authentication flaw in macOS Screen Sharing is leaving Apple devices exposed to unauthorized exploitation. The flaw allows attackers to bypass authentication and gain unauthorized administrative access by hijacking administrative access through the vulnerable desktop environment.
Some attackers have used compromised systems to deploy Monero mining software. Thus, security experts recommend installing Apple’s emergency updates immediately to avoid resource hijacking or serious performance issues.
Critical macOS Vulnerability Enables Unauthorized Monero Mining
Tracked as CVE-2026-65400, the flaw carries a critical CVSS severity rating of 9.8. Specifically, the bug relates to state management in the authentication system on the native Screen Sharing service.
Remote threat actors exploit this logic error by sending crafted packets directly to vulnerable machines. As a result, once they gain access, hackers have full administrative control, even if they do not know the system password or logon username.
Attackers can use elevated access to deploy malware, including cryptojacking software that installs stealthy Monero mining scripts. These rogue operations also consume hardware resources while running in the background as system processes.
Apple Mac Flaw Lets Hackers Turn Devices Into Monero Miners
Hackers exploited a flaw in Apple’s Screen Sharing feature to take control of internet reachable Macs.
The attackers then installed Monero monero:native mining software on compromised devices, Dutch authorities said.… pic.twitter.com/36IjOoiLay
— BSCN (@BSCNews) August 17, 2026
Understanding Port 5900 Exploitation and Monero Mining Mechanics
The exploit targets devices running port 5900 that are directly exposed to the open internet. Plus, automated scanning tools can detect accessible targets in minutes across a global network range.
Cybercriminals are opting for this privacy-focused cryptocurrency in opportunistic campaigns because they know how Monero is mined. Unlike Bitcoin, Monero uses the proof-of-work algorithm called RandomX, which is suitable for the common desktop CPU.
Moreover, RandomX is optimized for Apple Silicon and modern x86 CPU architectures. As a result, Mac equipment can mine and deliver high hash rates without needing special mining rigs.
Furthermore, Monero uses ring signatures and stealth addresses to hide transaction details entirely. As a result, bad actors can steal computing power while staying hidden from financial regulators.
Apple Security Updates Mitigate Unauthorized Monero Mining
Apple reacted quickly and issued emergency security patches for all supported OS versions. In particular, patches are available in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
Network administrators should check firewalls to ensure port 5900 is closed to external traffic. Or, if you turn off Screen Sharing in System Settings, you can disable any potential network attack immediately.
Applying the updates closes the Screen Sharing vulnerability and helps prevent this attack path from compromising corporate networks.
Overall, patch deployment saves important hardware resources from automated attack campaigns.
Monero’s selection is intentional. Monero has long been a target of cryptojacking, which involves running mining software on hijacked computers, due to the token’s ability to be mined on ordinary hardware rather than specialized rigs and the private nature of its transactions.