[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-hackers-are-exploiting-a-mac-screen-sharing-flaw-for-crypto-mining":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},4988,"hackers-are-exploiting-a-mac-screen-sharing-flaw-for-crypto-mining","Hackers Are Exploiting a Mac Screen Sharing Flaw for Crypto Mining","A high-severity flaw in macOS screen sharing let attackers gain root access and install Monero miners on systems reachable over the internet.","A patched macOS screen sharing bug is already being exploited by attackers to gain root access and mine cryptocurrency.\n\nThe Netherlands' National Cyber Security Centrum warned this week that CVE-2026-65400, a flaw in macOS's screen sharing feature, is under active attack on systems with port 5900 open to the internet. Screen sharing normally lets a remote party view a screen and control the keyboard and mouse; the bug lives in the \"state management\" code that tracks user interactions and system state. Apple rated the flaw 7.1 out of 10, high severity, not critical, and shipped a patch last week for macOS Tahoe, Sequoia, and Sonoma. The NCSC said every compromised system it examined ended up with root access and a Monero crypto miner installed.\n\nPort 5900 is VNC's default port, and exposing it directly to the internet has been a bad idea for decades. This attack succeeds because someone left that door open, not because Apple's screen sharing is uniquely broken. Still, a state-management bug that escalates to root is a serious design failure, and the fact that abuse began before most users had patched shows attackers are watching Apple's release notes as closely as security researchers do.\n\nIf your Mac has screen sharing enabled and reachable from outside your network, the crypto miner is the least of your problems: patch first, ask questions later.","[\"macos\",\"screen-sharing\",\"vulnerability\",\"crypto-mining\"]","2026-08-14T18:32:14.000Z","2026-08-15T03:31:16.014Z","2026-08-15T03:31:27.607Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek calls the flaw 'critical' while the body correctly labels it 'high-severity' at 7.1\u002F10 (CVSS 'critical' starts at 9.0) — fix the dek to match the body's accurate severity classification.","resolved","security",[32,33,34,35],"macos","screen-sharing","vulnerability","crypto-mining",[37],{"name":38,"url":39},"Ars Technica","https:\u002F\u002Farstechnica.com\u002Fsecurity\u002F2026\u002F08\u002Fvulnerability-giving-attackers-full-control-of-macs-is-under-active-exploitation\u002F",0,{"sections":42},[43,48,51,56,61,66,71,76,81,86,91,96,101,106],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":47},"Security",435,{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":107,"slug":108,"count":109,"latest_published_at":110},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]