DEV Community

Cover image for Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks

Summary

Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.

Take Action:

If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)