
Unpatched Macs With Screen Sharing Exposed Are Being Hijacked for Crypto Mining
Key takeaways
- CVE-2026-65400 allows passwordless root access via macOS screen sharing; patched last week for Tahoe, Sequoia, and Sonoma.
- Dutch NCSC confirmed active exploitation on systems with port 5900 open to the internet, with Monero miners installed.
- Users should install Apple's security update immediately and disable screen sharing when not in active use.
Apple has issued an emergency patch for CVE-2026-65400, a macOS vulnerability that lets remote attackers gain root-level control without a password — and Dutch officials say it is already being weaponized in the wild. The Netherlands National Cyber Security Centrum (NCSC) confirmed this week that multiple systems with port 5900 exposed to the internet have been compromised, with attackers dropping Monero cryptocurrency mining software on affected machines.
The flaw lives inside macOS's screen sharing subsystem, a built-in feature that lets authorized users remotely view and control a Mac's display, keyboard, and mouse. The specific failure is in 'state management' — the layer of software responsible for tracking user interactions, session variables, and system conditions. When that logic breaks down, a remote party can effectively slip past credential checks entirely, walking into an active session as if they belong there.
Apple rated the vulnerability 7.1 out of 10 on the standard severity scale and released patches for macOS Tahoe, Sequoia, and Sonoma last week. Technical details about CVE-2026-65400 were publicly disclosed at the Black Hat security conference, which likely accelerated exploitation attempts. Apple's official advisory stated the bug 'may' allow unauthorized access — language critics noted was unusually cautious, though hedging during initial disclosures is common practice across the industry.
The attack vector is narrow but significant: port 5900, which macOS automatically opens when screen sharing is enabled, must be reachable from the internet. Most home routers block this port by default, but misconfigured networks or deliberately forwarded ports leave machines exposed. Security professionals have long recommended routing screen sharing sessions through a VPN or SSH tunnel rather than exposing port 5900 directly — advice that unfortunately requires technical knowledge beyond most everyday Mac users.
For now, investigators have found no evidence that attackers are deploying anything beyond Monero miners, which quietly drain CPU resources to generate cryptocurrency for their operators. That could change rapidly. Once root access is established, an attacker could install credential-stealing malware, ransomware, or persistent backdoors. Apple's patch is available immediately, and users who have not yet installed last week's update should treat doing so as urgent.
The bigger picture
This incident illustrates a recurring tension in consumer operating system security: features designed for convenience become attack surfaces when deployed carelessly. Screen sharing is genuinely useful — for remote work, IT support, and family tech help — but Apple's decision to automatically open port 5900 on the macOS firewall whenever the feature is toggled on creates a risk that most users have no idea exists. Microsoft faces similar criticism with Remote Desktop Protocol on Windows, and both companies have been slow to push stronger defaults.
The competitive angle worth watching here is enterprise trust. macOS has spent years building a reputation as the 'safer' platform, winning significant ground in corporate environments where security teams once defaulted to Windows. Publicly confirmed, actively exploited root-access vulnerabilities — especially ones disclosed at Black Hat — chip away at that narrative. IT administrators at companies running fleets of MacBooks will be scrutinizing their port exposure this week, and some may accelerate deployment of third-party endpoint detection tools that Apple's own security stack doesn't provide out of the box.
The Monero mining payload is almost certainly not the end of this story. Criminal groups routinely use miners as a low-risk first foothold — they generate revenue while the operator decides whether a target is worth escalating. The NCSC's warning that 'multiple systems' were already hit suggests broad scanning activity is underway. Users running macOS with screen sharing enabled should update immediately, close port 5900, and audit their router's forwarding rules. Waiting for a second wave of more damaging payloads is not a strategy worth betting on.
We flagged this story because actively exploited vulnerabilities affecting major consumer platforms are exactly the kind of threat our readers need to hear about before they become a statistic. macOS security flaws don't get nearly the mainstream coverage that Windows vulnerabilities do, partly because of a long-held (and increasingly shaky) assumption that Macs are inherently safer. The Dutch government calling this out publicly is significant — national cybersecurity agencies rarely issue warnings unless exploitation is widespread enough to matter at scale. We also think the screen sharing angle deserves more attention: this isn't an obscure system service; it's a feature millions of people switch on for remote work or to help a family member troubleshoot a problem. If that description fits you, please install Apple's latest update today. We'll be watching for follow-up reports on whether more destructive payloads begin appearing on compromised systems.
As an Amazon Associate, LagPing earns from qualifying purchases. Product links are affiliate links.
You might also like

Rockstar Unleashes 99 GTA 6 Screenshots as November Launch Enters Final Countdown
Sep 1

Alleged Xbox Elite Series 3 Surfaces on OfferUp — And It Has a Screen on the Face
Aug 12

Screen Burn's Foggy Scottish Islands and Analog Dread Redefine Silent Hill's Future
Jul 31

How Every Screen in Your Life Surrendered to the Portrait Format
Jul 27