AUTO-UPDATED

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

The Dutch National Cyber Security Centre has confirmed active exploitation of a critical authentication vulnerability in macOS Screen Sharing, urging users to update their systems immediately to prevent compromise.

Key Points

  • The vulnerability, tracked as CVE-2026-65400, carries a critical CVSS score of 9.8 and allows unauthorized network access without valid credentials.
  • Apple released patches for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address the flaw discovered by researcher Alfredo Pesoli.
  • Attackers are actively targeting systems with port 5900 exposed to the internet to gain root access and install Monero cryptocurrency miners.
  • Security firm Calif reported that the logic-based flaw is simple to exploit, with functional attack code created in just four hours using AI tools.
  • Experts recommend disabling Screen Sharing in system settings if immediate software updates are not possible to mitigate the risk of unauthorized remote access.

Why it Matters

This incident highlights the rapidly shrinking window between the disclosure of a software vulnerability and the deployment of functional exploits by malicious actors. The ease of weaponizing these logic errors suggests that exposed network services face an immediate and high risk of automated compromise.
Securityaffairs.com Published by Pierluigi Paganini
Read original