PulseAugur
EN
LIVE 15:03:55

Critical macOS Screen Sharing flaw exploited for Monero cryptojacking

A critical vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by attackers to gain remote root access on Macs. The flaw allows unauthorized authentication, leading to the installation of Monero cryptocurrency miners. CISA has significantly increased the severity score of this bug from 7.1 to 9.8, classifying it as critical and automatable, following reports from the Dutch National Cyber Security Centre (NCSC-NL) and the availability of public proof-of-concept code. Apple released an out-of-band patch for this vulnerability on August 6th, covering several macOS versions, though it was not immediately added to CISA's Known Exploited Vulnerabilities catalog. AI

IMPACT Exploitation of this vulnerability could lead to widespread cryptojacking, impacting system availability and security for macOS users.

RANK_REASON The article details an exploited vulnerability and its impact, but focuses on a specific flaw in an existing product rather than a new release or significant industry shift.

Read on Tom's Hardware →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Critical macOS Screen Sharing flaw exploited for Monero cryptojacking

COVERAGE [1]

  1. Tom's Hardware TIER_1 English(EN) · Luke James ·

    Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks

    The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.