macOS Screen Sharing flaw already exploited in the wild to install crypto miners

macOS 26 Finder icon

A recently patched vulnerability in macOS Screen Sharing that let attackers gain remote control without credentials is now being actively exploited. The Netherlands’ National Cyber Security Center (NCSC-NL) reports attackers have used it to seize root access on exposed systems and install Monero crypto miners. Apple issued fixes in macOS Tahoe 26.6.1 (and corresponding updates for Sonoma and Sequoia); users who haven’t updated should do so immediately.

Tim Hardwick for MacRumors:

As first reported by ArsTechnica, the NCSC-NL said that it had been notified of abuse of the vulnerability, “observed on multiple systems on which port 5900 was accessible from the internet.” The reason is that when screen sharing is enabled, macOS’s firewall intentionally exposes this port. “In all these cases, root had been accessed on the affected system and a Monero crypto miner had been placed,” the NCSC-NL added. In other words, a targeted Mac’s resources are used to mine cryptocurrency. When pushing the fix – which was also included in macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9 – Apple said it had addressed the authentication issue with “improved state management.” Users who have not updated their Macs should do so as soon as possible.


MacDailyNews Take:


Please help support MacDailyNews — and enjoy subscriber-only articles, comments, chat, and more — by subscribing to our Substack: macdailynews.substack.com. Thank you!

Support MacDailyNews at no extra cost to you by using this link to shop at Amazon.

The post macOS Screen Sharing flaw already exploited in the wild to install crypto miners appeared first on MacDailyNews.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论