Critical macOS vulnerability turned Macs into hidden Monero mining farms.

I have discovered an alarming attack vector targeting Apple device owners. It involves the exploitation of a critical flaw in the Screen Sharing component, which allows attackers to gain full control over a Mac without any action on the part of the user.
During the analysis of incidents, it turned out that hackers used this vulnerability not only to steal confidential data, but also to secretly install Monero (XMR) miners. This turns infected computers into quiet "farms" for cryptocurrency mining, generating income for the attackers at the expense of victims' resources. The exact number of victims and the scale of the campaign remain unknown so far.
Evolution of the threat: from 7.1 to 9.8 points
Initially, the vulnerability, assigned identifier CVE-2026-65400, was given a risk rating of 7.1 out of 10. However, just two days later, the assessment was radically revised upward—to 9.8 points. This indicates an extremely high level of danger and ease of exploitation of the bug, which allows bypassing authentication mechanisms.
The root of the problem lies in the "Screen Sharing" feature. Although it is disabled by default, many users and administrators enable it for convenient remote access to their machines, which opens the "gate" for attackers. A search of open ports revealed tens of thousands of potentially vulnerable hosts worldwide.
Apple's response and emergency measures
Apple promptly released patches closing this vulnerability in the latest versions of operating systems: macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. I strongly recommend that all macOS users immediately install these updates to prevent possible hacking and unauthorized use of computing power.
This is not the first time macOS has become a target for sophisticated attacks. Previously, methods of bypassing Apple's security mechanisms using AI have already been demonstrated, highlighting the growing sophistication of cybercriminals.
My expert commentary: This incident is a stark reminder that mining botnets do not always require complex infrastructure. Using legitimate OS features for covert cryptocurrency mining is a trend that will gain momentum. Users should not only keep track of updates, but also check the activity of their devices for abnormal CPU load, which is often the first sign of infection with a hidden miner.