macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation
macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation 1. Basic Information Severity: Critical Title: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner Source: BleepingComputer Published Date: 2026-08-14 Updated Date: N/A Original Article: Original Article Related Sources: Apple Security , NCSC-NL NCSC-2026-0280 Malware: Monero…
An authentication vulnerability in macOS Screen Sharing, CVE-2026-65400, has been exploited by hackers to gain root access and install a Monero cryptocurrency miner. This flaw allows attackers to connect to the Screen Sharing service from the internet and authenticate without valid credentials. Once authenticated, they can launch applications, access files, and modify security settings.
In some cases, attackers have managed to obtain root access. To mitigate this risk, it is recommended to update macOS to the latest versions (Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9, or later), disable Screen Sharing if not needed, block TCP/5900 from the internet, and monitor for suspicious activities like root processes and Monero miner installations.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.