Hackers Exploit macOS Screen Sharing Vulnerability to Mine Monero

iconKuCoinFlash
Share
AI summary iconSummary
Hackers are exploiting a macOS screen sharing vulnerability (CVE-2026-65400) to mine Monero, according to a new vulnerability alert from Odaily. The flaw, rated 7.1/10, enables attackers to bypass login authentication and obtain root access. Apple has released patches for Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC urges users to update their systems and secure their screen sharing settings. The scale of this DeFi exploit underscores the need for immediate action.

Odaily Planet Daily reports that attackers are exploiting a vulnerability in Apple’s macOS Screen Sharing feature to take control of devices and install Monero mining software. Multiple systems exposing port 5900 to the internet have been compromised, with attackers gaining root access. The vulnerability, identified as CVE-2026-65400, has a severity score of 7.1 out of 10, stemming from a state management flaw in the authentication process that allows remote attackers to bypass login verification without valid credentials. A public proof-of-concept code is already circulating. Apple has patched this issue in macOS Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1. The NCSC advises users to update their systems promptly and avoid exposing Screen Sharing services directly to the internet. (Decrypt)

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.