Security/ macos · screen-sharing · cryptojacking · cisa

macOS Screen Sharing Flaw Rated Critical After Attacks

CISA raised a macOS Screen Sharing bug to critical severity days after attackers used it to root Macs and mine Monero for cash.

A patched macOS bug just got a lot scarier: CISA now rates it critical, and it's already being used to hijack Macs for cryptocurrency mining.

Apple fixed CVE-2026-65400, an authentication bypass in Screen Sharing (its built-in VNC-based remote desktop service on port 5900), on August 6 with an out-of-band update for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The Dutch National Cyber Security Centre reported on August 12 that attackers were actively exploiting the flaw on internet-exposed Macs, gaining root access in every reported case and installing Monero miners. Technical details and a working exploit were also shown at Black Hat last week, and public proof-of-concept code is now circulating. On August 14, CISA rewrote the bug's severity score from 7.1 to 9.8, swapping an attack model that assumed existing privileges for one requiring none at all.

The jump from 7.1 to 9.8 isn't just a paperwork update - it's an admission that the bug was scored wrong while it was already being exploited in the wild. CISA's own decision record still lists exploitation as "none" and hasn't added the flaw to its Known Exploited Vulnerabilities catalog, even after a national cybersecurity agency confirmed active attacks. That gap between official tracking and what's actually happening on the internet is the more interesting story here, not the cryptojacking itself.

Screen Sharing is off by default, so this only bites Macs someone deliberately exposed to the internet - which, going by the attackers' apparent success, turns out to be more Macs than you'd hope.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →