Crypto news

17.08.2026
09:40

Critical macOS vulnerability allowed hackers to inject hidden Monero mining on Mac

social network hacking

An alarming signal has flared up again in the world of cybersecurity: the Netherlands' National Cyber Security Centre (NCSC) has identified active exploitation of a dangerous flaw in the Screen Sharing component on Mac devices. This concerns an attack vector that allowed attackers not only to gain full control over the system but also to stealthily deploy hidden Monero (XMR) cryptocurrency miners.

According to my data, attackers used this vulnerability to steal confidential information and install malicious mining software. At the same time, neither the exact number of victims nor the scale of the groups behind these attacks has been officially disclosed, leaving wide room for speculation about the true extent of the threat.

Rating escalation and Apple's response

The initial report on the vulnerability, identified as CVE-2026-65400, was published on August 12. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) initially assessed the risk at 7.1 points out of 10, which is already a high figure. However, just two days later, experts revised their assessment, raising the rating to a critical 9.8 points. This is an unprecedented step that underscores the severity of the issue and the ease of its exploitation.

In response, Apple promptly released fixes as part of updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Based on the technical description, the bug allowed a remote attacker to gain unauthorized access to a Mac via Screen Sharing, effectively bypassing authorization mechanisms.

It is important to note that the "screen sharing" feature is not enabled by default on most devices. However, it is a standard tool for IT administrators and users who configure remote access to their machines or servers. It is these groups that are at heightened risk.

Scope of the threat and recommendations

Independent researchers, particularly from the company Huntress, analyzed open data and found tens of thousands of potentially vulnerable hosts worldwide. This indicates that the attack was not targeted but widespread in nature. macOS users are strongly advised to immediately install the latest security updates to close this gap.

This incident is yet another reminder that even ecosystems with high levels of protection, such as Apple's, are not immune to sophisticated attacks. Earlier this year, we already saw how AI models helped researchers bypass macOS defense mechanisms, and now we are observing the practical application of such knowledge for criminal purposes. In the current environment, where digital assets are becoming an increasingly attractive target, ignoring security updates is a direct threat not only to your data but also to your wallet.