Meet the Top 101 in Crypto
News
3 min read

Your Mac Could Be Mining Monero (XMR) for Hackers — Apple Issues Emergency Fix

Published 18 August 2026
Dr. Guneet Kaur
Authors

Key Takeaways

  • Hackers are actively exploiting a macOS Screen Sharing flaw to gain root access and install Monero mining software.
  • Apple patched the vulnerability on Aug. 6, but Macs running older versions remain exposed if Screen Sharing is reachable from the internet.
  • CISA now rates the bug 9.8 out of 10, after initially assigning it a much lower severity score.

Hackers are turning vulnerable Macs into Monero mining machines by exploiting a critical flaw in Apple’s built-in Screen Sharing feature.

The vulnerability, tracked as CVE-2026-65400, allows an attacker to authenticate to Screen Sharing without valid credentials. Apple released fixes on Aug. 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9.

Apple described the bug as an authentication problem caused by flawed state management. What initially appeared to be another macOS security patch has since become more urgent as evidence of real-world attacks has surfaced.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Experience a 1-minute swap on a non-custodial platform.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217
Show More

Hackers Are Already Using the Bug to Mine Monero (XMR)

The Netherlands’ National Cyber Security Centre said on Aug. 12 that it had received reports of the vulnerability being exploited across multiple systems where port 5900, used by Screen Sharing, was exposed to the internet.

In every case reported to the agency, attackers gained root access and installed a Monero cryptocurrency miner. Public proof-of-concept code is also available, increasing the risk that more attackers could reproduce the exploit.

Root access gives an attacker extensive control over a Mac. In the attacks identified so far, that control was used for cryptojacking, where a victim’s computing power is quietly redirected to mine cryptocurrency for someone else.

Security firm Huntress found that CVE-2026-65400 affects the Secure Remote Password authentication process used by Screen Sharing. A flaw in the process can cause an unauthenticated connection to be treated as authenticated, allowing malicious code to run without the attacker first logging into the machine.

Hosted Macs may be especially exposed because remote-access services such as Screen Sharing are more commonly enabled on machines used for remote workloads. Huntress said internet scans show tens of thousands of potentially exposed systems.

Apple Patch Becomes More Urgent

The vulnerability’s risk rating has also climbed sharply.

CISA now assigns CVE-2026-65400 a 9.8 critical CVSS score, with the assessment showing that exploitation requires no prior privileges or user interaction and can result in major confidentiality, integrity and availability losses.

Mac users running Screen Sharing should update to Tahoe 26.6.1, Sequoia 15.7.9 or Sonoma 14.8.9.

For users who cannot update immediately, disabling Screen Sharing removes the exposed service. Changing a Screen Sharing password alone is not enough because the vulnerability can be exploited before normal authentication takes place.

So far, authorities have not disclosed how many Macs have been compromised or how much Monero attackers have mined through infected machines.

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Dr. Guneet Kaur

Dr. Guneet Kaur is a senior editor at CCN.com and a Science Fellow at Exponential Science. She is a fintech and blockchain expert with extensive experience in digital finance education, blockchain ecosystems, and cryptocurrency markets. She has worked with global media such as Cointelegraph, as well as education and blockchain platforms, to design and lead strategic content and learning initiatives. As an educator and assessor for top-tier executive programs, she bridges real-world fintech trends with academic insight.

Dr. Kaur is also a published researcher and peer reviewer across fintech and data science journals, including Financial Innovation Journal and International Journal of Big Data Intelligence and Applications. Her work spans data-driven analysis, Web3 innovation, and technical content development. With a strong foundation in both industry and academia, she translates complex financial technologies into practical applications, empowering learners, professionals, and institutions across the rapidly evolving digital finance landscape.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status