
Hackers are exploiting a newly patched flaw in Apple’s Mac screen-sharing feature to take control of vulnerable computers and secretly mine Monero, according to the Netherlands’ National Cyber Security Centre (NCSC-NL).
The agency confirmed on August 13 that attackers are actively exploiting the vulnerability, tracked as CVE-2026-65400.
Sponsored
The flaw allows attackers to bypass authentication in macOS Screen Sharing and gain high-level access to affected Macs, which they can then use to install cryptocurrency-mining malware.
The attack is a form of cryptojacking: instead of stealing cryptocurrency from a wallet or exchange, criminals hijack someone else’s computing power and use it to generate crypto.
Apple released an emergency security update on August 6. But Macs that have not been patched — particularly those with Screen Sharing exposed directly to the internet — remain at risk.
How the Mac attack works
The vulnerability affects screensharingd, the macOS component responsible for the operating system’s built-in remote-access feature.
The flaw allows a network-based attacker to get past Screen Sharing’s normal authentication checks without valid credentials. Once access is obtained, attackers can gain root-level control of the Mac and install additional software.
NCSC-NL said that in every compromise it observed, attackers installed a Monero miner.
Security researchers at Huntress also found that common attempts to secure Screen Sharing, such as changing the password or removing authorized accounts, do not prevent exploitation of the underlying vulnerability. Patching the operating system or disabling Screen Sharing entirely is required to close the attack path.
Huntress noted that the risk is compounded by the rise of hosted bare-metal Mac services, such as cloud-based Mac minis, which often ship with Screen Sharing enabled by default. A search on the internet-scanning platform Censys turned up tens of thousands of potentially vulnerable hosts tied to such providers, according to Huntress.
Apple’s fixes cover macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Why Monero?
Monero (XMR) can be mined using general-purpose computer processors, and its privacy features can make some transactions more difficult to trace.
XMR uses a proof-of-work algorithm called RandomX, which is designed to run on general-purpose CPUs rather than the specialized mining hardware commonly used to mine Bitcoin and some other cryptocurrencies.
For attackers, this can reduce the cost of running a mining operation. They can use victims’ computing power and electricity to mine Monero rather than purchasing and operating their own hardware.
Monero also has privacy features designed to obscure the identities of parties to transactions, making some transactions more difficult to trace. Those features have drawn increased regulatory scrutiny in some jurisdictions, particularly in the context of anti-money-laundering measures.
Why This Matters
Attackers can use victims’ Macs and electricity to mine crypto, shifting the cost of the mining operation to the victim. The extra CPU usage can also slow the affected computer and increase energy consumption.
Dive into DailyCoin’s hottest crypto news today:
Trezor Warns of Phishing Risk After 14,000-Customer Data Leak
How Stablecoin Regulation Drives Blockchain Innovation 2026