Apple Patches macOS Zero-Day Exploited for Monero Mining

0
1

Key Takeaways

  • Apple patched a critical Screen Sharing vulnerability (CVE-2026-65400) that allowed unauthenticated attackers to gain root access on internet‑exposed Macs.
  • The flaw resides in the SCRAM authentication mechanism; once exploited, attackers installed Monero‑mining software to hijack the host’s CPU power.
  • The Dutch National Cyber Security Centre (NCSC) observed active exploitation on port 5900, noting tens of thousands of exposed hosts via Censys scans, though the exact number of compromised machines remains unknown.
  • Hosted bare‑metal Macs are especially vulnerable because Screen Sharing may be left enabled during automated provisioning.
  • Mitigation: apply Apple’s security updates for macOS Tahoe, Sequoia, and Sonoma, or disable Screen Sharing until patching is complete.

Introduction
In mid‑August 2026, a widespread cryptojacking campaign targeting macOS machines came to light after the Netherlands’ National Cyber Security Centre (NCSC) reported that attackers were exploiting a previously unknown vulnerability in Apple’s Screen Sharing service. The flaw enabled threat actors to obtain full administrative (root) privileges on Macs exposed to the internet, after which they deployed Monero‑mining software to harness the victims’ processing power for cryptocurrency generation. The incident highlights the risks associated with leaving remote‑management services openly accessible and underscores the importance of timely patch management.


Vulnerability Details and Discovery
The vulnerability, tracked as CVE-2026-65400, is a state‑management error in the Screen Sharing component that affects the Secure Remote Password (SCRAM) authentication mechanism. According to analysis by security firm Huntress, the flaw allows an unauthenticated network connection to be mistakenly treated as an authenticated one, bypassing the normal login process and granting the attacker immediate root privileges. Because the bypass occurs before any credential verification, traditional mitigations such as password changes or account disabling are ineffective. The NCSC first observed active exploitation on August 12, 2026, noting that attackers were targeting systems reachable via TCP port 5900, the default port for Screen Sharing.


Apple’s Response and Patch Release
Apple addressed the issue swiftly, releasing security updates for macOS Tahoe, Sequoia, and Sonoma on August 6, 2026—six days prior to the NCSC’s public disclosure. The updates correct the faulty state handling in the SCRAM flow, ensuring that only properly authenticated sessions can proceed to privileged operations. Apple’s advisory emphasizes that users running any of the affected macOS versions should install the update immediately, especially if Screen Sharing is enabled and reachable from the internet.


Technical Explanation of the Exploit
Huntress elaborated that the bug lies in how the Screen Sharing daemon validates the authentication state after a client initiates a SCRAM exchange. A malformed sequence of messages can cause the daemon to skip the final verification step, thereby marking the session as authenticated despite the absence of valid credentials. This premature authentication grants the remote user the same privileges as a legitimate administrator, allowing execution of arbitrary commands with root access. The exploit requires no user interaction; merely sending crafted packets to port 5900 suffices.


Impact: Monero Mining Campaign
Once root access was achieved, attackers deployed a Monero (XMR) miner designed to run stealthily in the background, consuming CPU cycles to generate cryptocurrency. The Dutch NCSC reported that the primary motive was resource hijacking rather than data theft or wallet exfiltration. The mining activity was observed across numerous infected hosts, although the NCSC did not disclose the exact count of compromised machines, the specific mining‑pool addresses, or the total amount of XMR generated. At the time of writing, Monero traded around $417, having risen roughly 2% in the preceding 24 hours and nearly 6.7% over the past week—price movements unrelated to the scale of the mining operation.


Broader Context of macOS Cryptojacking
Monero’s suitability for CPU‑based mining on commodity hardware has made it a frequent target for cryptojacking campaigns across operating systems. This incident adds to a growing trend of macOS‑focused crypto attacks, which include both covert mining malware and more direct threats aimed at cryptocurrency exchanges and wallet services. The ease with which attackers can leverage built‑in remote‑management features like Screen Sharing amplifies the threat surface, particularly in environments where automation scripts provision new Macs with remote access enabled by default.


Mitigation Recommendations
Security experts, including Huntress, advise a two‑pronged approach: first, apply Apple’s security patches without delay; second, restrict or disable Screen Sharing on systems that do not require remote access, especially those directly exposed to the internet. For infrastructures that rely on automated Mac provisioning, administrators should verify that Screen Sharing is disabled post‑deployment or enforce firewall rules that block inbound connections to port 5900 from untrusted networks. Regular vulnerability scanning and monitoring for anomalous CPU usage can also help detect residual infections before they cause significant performance degradation or increased electricity costs.


Conclusion
The CVE-2026-65400 Screen Sharing vulnerability exemplifies how a seemingly benign administrative feature can become a powerful entry point for attackers when left unpatched and exposed. Apple’s rapid release of fixes for macOS Tahoe, Sequoia, and Sonoma mitigates the immediate risk, but the episode serves as a reminder that continuous vigilance—prompt patching, service hardening, and network segmentation—is essential to protect Mac endpoints from cryptojacking and other privilege‑escalation threats. By following the outlined mitigation steps, organizations can significantly reduce the likelihood of similar exploits compromising their Apple‑based assets.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here