macOS Screen Sharing bug, rated 9.8, mined Monero on internet-facing Macs, Dutch agency says

A critical flaw in Apple’s Screen Sharing feature let attackers quietly install Monero (XMR) cryptomining software on internet-facing Macs, the Netherlands’ National Cyber Security Centre said in an advisory.

The vulnerability scored 9.8 out of 10 on the CVSS severity scale, the highest band. It is now patched. Apple shipped the fix on Aug. 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, writing in a support note that an attacker on the network could reach a Mac through Screen Sharing without a valid password.

Screen Sharing is off by default. Researchers say it is commonly switched on for “bare-metal” Mac servers hosted remotely, exactly the kind of machine left exposed.

The flaw is tracked as CVE-2026-65400. CISA first rated it 7.1 the day Apple pushed the patch, then revised the score to 9.8 on Friday, per an NVD record. As of publication the bug had not yet been added to the federal catalog of vulnerabilities known to be under active attack.

“Anybody who uses Apple’s Screen Sharing functionality on any supported macOS version needs to apply the most recent security updates immediately,” Ryan Dowd, a researcher at Huntress, wrote. He said he had identified “tens of thousands of potentially vulnerable hosts” through a Censys search.

That figure measures exposure, not confirmed infections. The NCSC did not say how many machines were compromised. It did not name a suspected actor.

The bug fails before authentication, according to Huntress’s analysis. The Mac treats a stranger’s connection as one that has already logged in, Dowd wrote. Changing or deleting Screen Sharing passwords does not help. The patch is the fix.

Monero has long been the favorite of cryptojacking operators. It mines on ordinary processors, no specialized rigs needed, and its transactions are private. The whole Monero network issues roughly 432 XMR a day, worth about $179,000 at Sunday’s price, split among all miners. XMR traded at $415.82 on Sunday, up about 3.7% over 24 hours, per The Block.

Crypto-mining malware rarely makes the front page next to exchange breaches. It keeps happening anyway. In March, an Alibaba-affiliated AI agent called ROME diverted GPUs from its own training runs to mine crypto, according to a technical paper from the teams that built it.

Apple and the NCSC did not immediately respond to The Block’s requests for comment.

> ABOUT_THE_AUTHOR _

James Chatfield

// Senior News Editor

I lead the editorial team covering digital assets and blockchain regulation at CryptoWatchDaily. After earning a Journalism degree from The University of Sheffield, I spent a decade reporting on traditional finance before shifting focus to crypto. I value accuracy and clarity over hype. When I’m not tracking market movements, I enjoy distance running and collecting vintage sci-fi novels.

VIEW_PROFILE >>