Key Highlights
- Attackers are using a macOS flaw to install Monero mining software on Macs.
- Every case reported to Dutch authorities ended in full administrator access.
- US authorities raised the flaw’s severity score from 7.1 to 9.8 on August 14.
Attackers are exploiting a flaw in Apple’s Screen Sharing feature to seize root access—full administrator control—of Macs reachable over the internet and using it to install software that mines Monero.
US cyber authorities raised the flaw’s severity score to 9.8 out of 10 on August 14, after Dutch officials confirmed attacks were already under way.
Attackers are breaking into Macs over the internet and installing software that mines Monero, using a flaw in Apple’s Screen Sharing feature that the company patched on August 6.
Every Reported Case Ended the Same Way
The Netherlands’ National Cyber Security Centre said that it had received a report of the flaw being actively abused on multiple systems. In every case, attackers obtained root access and installed a Monero mining program.
All the affected systems had port 5900 reachable from the internet. That is the network port Apple’s screen sharing uses, and leaving it open to the public internet is what allowed attackers to reach the vulnerable feature from outside.
The agency did not say how many machines were affected, when the attacks began, or who was behind them.
Why Attackers Choose Monero
Mining is the process of running calculations that verify transactions on a blockchain in exchange for newly created coins. Installing mining software on someone else’s computer without permission is known as cryptojacking. The victim pays the electricity bill and loses processing power; the attacker keeps the coins.
Monero is designed to obscure the sender, receiver, and amount of every transaction, which makes proceeds harder to trace than Bitcoin. It can also be mined efficiently on ordinary computer processors rather than specialist hardware, which makes hijacked laptops and desktops worth using.
Severity Score Raised After Attacks Began
CISA first scored it 7.1 out of 10 on August 6, assessing that an attacker would need some level of access to the machine. On August 14 the agency replaced that assessment with one requiring no access at all and granting complete compromise of the system, raising the score to 9.8. A separate record the following day changed its assessment of whether the attack can be automated from no to yes.
The agency’s record still lists exploitation as “none,” despite the Dutch advisory published two days earlier. NIST’s own National Vulnerability Database has not issued a score for the flaw. Both entries are visible in the change history on the NVD listing.
Apple described the problem as an authentication issue that it addressed with improved state management. In plain terms, the feature could be tricked into treating a stranger as a logged-in user. Apple credited security researcher Alfredo Pesoli of Bynario Atlas with reporting it.
The Dutch advisory also noted on August 12 that the working attack code had been published publicly, which typically widens the pool of people able to carry out an attack.
Changing Your Password Will Not Help
Because the flaw defeats the login check itself, the usual protective steps do not work. Security firm Huntress found that removing allowed user accounts, disabling legacy VNC password authentication, and rotating the VNC password all have no effect, because the bypass happens before any of those controls are consulted.
Huntress also reported the result as pre-authenticated remote code execution on all supported macOS versions, meaning an attacker can run their own software on the machine without ever logging in.
There are two fixes. Update to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9, all released on August 6. Or turn Screen Sharing off entirely, under System Settings, then General, then Sharing.
Anyone running a Mac that is reachable from the internet should also check whether port 5900 is open to the public.
Six Days From Patch to Attacks
Apple released the updates on August 6 outside its normal schedule. The Dutch agency published its first advisory on August 7, then updated it on August 12 to record that working attack code had been published publicly and that active abuse had been observed.
The gap matters because attackers often study a patch to work out what it fixed, then target machines whose owners have not installed it yet. Macs that were updated promptly were never at risk from these attacks; those still running older versions remain exposed.
Apple devices have drawn steady attention from attackers targeting crypto users. The Crypto Times reported in April on a macOS campaign attributed to the Lazarus Group aimed at crypto and fintech employees and in 2024 on macOS malware that replaced wallet applications with tampered versions to steal recovery phrases.
