Critical macOS Screen Sharing Flaw Exploited to Hijack Systems for Cryptocurrency Mining
Cybercriminals are actively exploiting a critical vulnerability in macOS Screen Sharing to hijack vulnerable Mac computers and deploy unauthorized cryptocurrency miners. The security flaw, tracked as CVE-2026-65400, allows attackers to bypass authentication protocols, gain administrative root access, and utilize the target system's resources to mine Monero.
According to security researchers and a confirmation from the Dutch National Cyber Security Centre (NCSC), the attacks specifically target macOS systems that have port 5900 exposed to the public internet. Port 5900 is the default port utilized by Apple's Screen Sharing feature and Virtual Network Computing (VNC) services. When left unprotected and accessible from the outside world, this port serves as an entry point for malicious actors scanning the web for exploitable targets.
Once the attackers exploit the authentication bypass vulnerability, they gain root-level privileges over the compromised macOS machine. This level of access grants them complete control over the operating system, allowing them to execute arbitrary commands, modify system files, and install software without the user's knowledge. In these observed attacks, the primary payload is a Monero miner, a type of software that secretly uses the computer's processing power to mine cryptocurrency—a practice known as cryptojacking.
For affected Mac users, the consequences of a cryptojacking infection typically manifest as sudden and severe performance degradation. Because cryptocurrency mining is an incredibly resource-intensive process, compromised systems will often suffer from sluggish responsiveness, overheating, and loud fan noise as the hardware runs at maximum capacity. Additionally, prolonged exposure can lead to increased electricity costs and potential hardware wear and tear.
To mitigate the risk of exploitation, cybersecurity experts strongly advise Mac administrators and users to ensure that port 5900 is not exposed directly to the public internet. If remote screen sharing is necessary, it should be secured behind a Virtual Private Network (VPN) or restricted to authorized IP addresses. Users are also urged to apply the latest security updates from Apple as soon as they become available to patch the underlying vulnerability.
This campaign highlights a growing trend of threat actors targeting macOS environments, which were historically perceived as less vulnerable to such automated attacks than their Windows counterparts. As cybercriminals continue to refine their tactics and scan for open ports, maintaining robust network hygiene and prompt patch management remains essential for safeguarding enterprise and personal Apple devices alike.
Comments (0)
Be the first to comment.
Join the discussion