macOS Screen Sharing Flaw Allows Attackers Remote Root Access
A critical macOS Screen Sharing flaw has been exploited by attackers to gain remote root access and install Monero cryptocurrency miners on vulnerable Macs.
## Critical macOS Screen Sharing Flaw Exposed A critical flaw in macOS Screen Sharing has been exploited by attackers to gain remote root access and install Monero cryptocurrency miners on vulnerable Macs. The Dutch National Cyber Security Centre (NCSC-NL) reported that attackers are actively exploiting the flaw, which was patched by Apple on August 6 in an out-of-band update. ## Attackers Gain Root Access and Install Monero Miners In every case reported to the NCSC-NL, attackers obtained root access and installed a Monero cryptocurrency miner after exploiting the flaw. The attack is made possible by an authentication bypass in macOS Screen Sharing, which is the VNC-based remote desktop service built into macOS. The service listens on TCP port 5900, which is disabled by default. ## CISA Raises Severity of the Flaw The Cybersecurity and Infrastructure Security Agency (CISA) has raised the severity of the flaw from 7.1 to 9.8 critical, following active Monero cryptojacking attacks. The agency has also assessed the attack as automatable, meaning that it can be carried out without human intervention. ## Technical Details of the Bug Presented at Black Hat Conference Technical details of the bug were presented at the Black Hat conference, alongside a video of the exploit in action. The root-level access attackers gained in the reported incidents matches the level of control researchers demonstrated in May, when they bypassed Memory Integrity Enforcement on Apple's M5 silicon with AI assistance. ## Users Advised to Update Immediately The NCSC-NL has advised organizations to update immediately, as public proof-of-concept code is now available and active abuse has been observed on multiple internet-exposed systems. Users who cannot update immediately can turn Screen Sharing off under System Settings > General > Sharing. ## Apple's Advisory and Patch Apple's advisory says an attacker on the network may be able to "authenticate to Screen Sharing without valid credentials," and describes the fix as improved state management during authentication. The August 6 update comes just 10 days after Apple's July 27 security round and fixes only this single CVE, representing the second Screen Sharing patch in a month. ## CVE-2026-65400 Details CVE-2026-65400 is an authentication bypass in macOS Screen Sharing, which allows attackers to gain remote root access and install Monero cryptocurrency miners on vulnerable Macs. The flaw was patched by Apple on August 6 in an out-of-band update, but its official severity has since been rewritten, with CISA raising its CVSS score from 7.1 to 9.8 critical on August 14. ## Users' Action Required Users are advised to update their macOS to the latest version as soon as possible to prevent exploitation of the flaw. Turning off Screen Sharing is also recommended for users who cannot update immediately.