Hackers exploited a flaw in Apple‘s Screen Sharing feature to gain root access to internet-exposed Macs and install Monero cryptocurrency miners, according to the Netherlands’ National Cyber Security Centre.
- Hackers exploited a flaw in Apple's Screen Sharing feature to gain root access to internet-exposed Macs and install Monero cryptocurrency miners, according to the Netherlands' National Cyber Security Centre.
- The affected releases included macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
- Users running older versions of macOS remain exposed if the vulnerable Screen Sharing service is reachable by attackers.
The NCSC said it received reports of active exploitation on multiple systems with port 5900 reachable from the internet. Apple released security updates on Aug. 6 after the flaw was disclosed, but Macs that remain unpatched can still be exposed.
Hackers Gained Root Access
The vulnerability affects macOS Screen Sharing, Apple’s built-in remote-access service. Attackers were able to bypass authentication and gain control of affected systems when the service was exposed to the internet.
The NCSC said the reported attacks all followed the same pattern. “In all these cases, root access had been obtained on the affected system and a Monero crypto miner had been placed,” the agency said in its advisory.
Root access gives an attacker the highest level of control over a Mac. It can allow software to be installed, files to be changed and system processes to be controlled.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseMonero Miners Installed
The attackers used that access to install cryptocurrency-mining software. The software uses the compromised computer’s processing power to calculate hashes for the Monero network, with the resulting cryptocurrency going to the miner’s operators.
The NCSC said the systems involved were reachable through port 5900, the network port commonly associated with VNC and Screen Sharing connections. The agency’s warning focused on systems where the service was accessible from the public internet.
The attacks did not require the attackers to first obtain the victims’ Mac passwords. The Screen Sharing flaw affected the authentication process itself, allowing an attacker to get past a security check and reach the system.
Apple Released Emergency Updates
Apple addressed the vulnerability in security updates released Aug. 6. The affected releases included macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.
Apple’s security documentation identifies the affected component as the Screen Sharing Server and describes the fix as an improvement to authentication state management.
The NCSC advised organizations and users to install the available updates. Systems that cannot be updated immediately should have unnecessary remote-access services disabled or restricted from public networks.
Internet-Exposed Macs Were Targeted
Screen Sharing is designed to let users remotely access and control a Mac. The service becomes a security risk when it is exposed directly to the internet without sufficient network restrictions.
The NCSC’s reported cases involved systems that were reachable through port 5900. That does not mean every Mac with Screen Sharing enabled was vulnerable to the observed attacks, but internet-facing systems presented a direct route for attackers to attempt exploitation.
The agency did not provide a total number of compromised Macs in the cases it reported. It also did not say how much cryptocurrency the attackers generated from the mining activity.
The Flaw Was Already Being Exploited
The key development was the discovery of attacks against real systems rather than the vulnerability remaining confined to security research.
The NCSC reported multiple cases in which attackers successfully obtained root access and installed Monero miners. That placed the flaw among vulnerabilities with a demonstrated path from remote access to system compromise and cryptocurrency mining.
Apple’s updates closed the affected security weakness. Users running older versions of macOS remain exposed if the vulnerable Screen Sharing service is reachable by attackers.
Macs Can Be Used For Cryptojacking
Cryptojacking is the unauthorized use of another person’s computer resources to mine cryptocurrency. Instead of stealing coins already stored in a wallet, attackers install mining software and use the victim’s processor to generate new cryptocurrency.
Monero has been used in cryptojacking campaigns because its mining algorithm is designed to work on general-purpose computer processors. That makes compromised desktops and servers useful targets.
In this case, the attackers did not need to persuade victims to install a malicious application. The reported intrusions began with the Screen Sharing vulnerability and ended with miners running under root access.
Apple has patched the flaw, but the reported exploitation shows the risk for Macs with remote-access services exposed to the internet. The immediate defensive measure is to update affected macOS versions and restrict Screen Sharing access to trusted networks.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





