Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    Binance Account Rental Scam: How Fraudsters Lure Crypto Users with Promises of Easy Money
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Hackers Exploit Apple Screen Sharing Flaw to Mine Monero on Macs

US cyber authorities raised the flaw's severity score to 9.8 out of 10 on August 14, after Dutch officials confirmed attacks were already under way.

Written By Dhara Chavda
Edited by Divya Mistry
Published 46 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Hackers Exploit Apple Screen Sharing Flaw to Mine Monero on Macs

Key Highlights

  • Attackers are using a macOS flaw to install Monero mining software on Macs.
  • Every case reported to Dutch authorities ended in full administrator access.
  • US authorities raised the flaw’s severity score from 7.1 to 9.8 on August 14.

Attackers are exploiting a flaw in Apple’s Screen Sharing feature to seize root access—full administrator control—of Macs reachable over the internet and using it to install software that mines Monero.

US cyber authorities raised the flaw’s severity score to 9.8 out of 10 on August 14, after Dutch officials confirmed attacks were already under way.

Attackers are breaking into Macs over the internet and installing software that mines Monero, using a flaw in Apple’s Screen Sharing feature that the company patched on August 6.

Every Reported Case Ended the Same Way

The Netherlands’ National Cyber Security Centre said that it had received a report of the flaw being actively abused on multiple systems. In every case, attackers obtained root access and installed a Monero mining program.

All the affected systems had port 5900 reachable from the internet. That is the network port Apple’s screen sharing uses, and leaving it open to the public internet is what allowed attackers to reach the vulnerable feature from outside.

The agency did not say how many machines were affected, when the attacks began, or who was behind them.

Why Attackers Choose Monero

Mining is the process of running calculations that verify transactions on a blockchain in exchange for newly created coins. Installing mining software on someone else’s computer without permission is known as cryptojacking. The victim pays the electricity bill and loses processing power; the attacker keeps the coins.

Monero is designed to obscure the sender, receiver, and amount of every transaction, which makes proceeds harder to trace than Bitcoin. It can also be mined efficiently on ordinary computer processors rather than specialist hardware, which makes hijacked laptops and desktops worth using.

Severity Score Raised After Attacks Began

CISA first scored it 7.1 out of 10 on August 6, assessing that an attacker would need some level of access to the machine. On August 14 the agency replaced that assessment with one requiring no access at all and granting complete compromise of the system, raising the score to 9.8. A separate record the following day changed its assessment of whether the attack can be automated from no to yes.

The agency’s record still lists exploitation as “none,” despite the Dutch advisory published two days earlier. NIST’s own National Vulnerability Database has not issued a score for the flaw. Both entries are visible in the change history on the NVD listing.

Apple described the problem as an authentication issue that it addressed with improved state management. In plain terms, the feature could be tricked into treating a stranger as a logged-in user. Apple credited security researcher Alfredo Pesoli of Bynario Atlas with reporting it.

The Dutch advisory also noted on August 12 that the working attack code had been published publicly, which typically widens the pool of people able to carry out an attack.

Changing Your Password Will Not Help

Because the flaw defeats the login check itself, the usual protective steps do not work. Security firm Huntress found that removing allowed user accounts, disabling legacy VNC password authentication, and rotating the VNC password all have no effect, because the bypass happens before any of those controls are consulted.

Huntress also reported the result as pre-authenticated remote code execution on all supported macOS versions, meaning an attacker can run their own software on the machine without ever logging in.

There are two fixes. Update to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9, all released on August 6. Or turn Screen Sharing off entirely, under System Settings, then General, then Sharing.

Anyone running a Mac that is reachable from the internet should also check whether port 5900 is open to the public.

Six Days From Patch to Attacks

Apple released the updates on August 6 outside its normal schedule. The Dutch agency published its first advisory on August 7, then updated it on August 12 to record that working attack code had been published publicly and that active abuse had been observed.

The gap matters because attackers often study a patch to work out what it fixed, then target machines whose owners have not installed it yet. Macs that were updated promptly were never at risk from these attacks; those still running older versions remain exposed.

Apple devices have drawn steady attention from attackers targeting crypto users. The Crypto Times reported in April on a macOS campaign attributed to the Lazarus Group aimed at crypto and fintech employees and in 2024 on macOS malware that replaced wallet applications with tampered versions to steal recovery phrases.

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto HackUnited States
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Renaissance Technologies Boosts Stake in Bitcoin Treasury Giant Strategy
Renaissance Technologies Boosts Stake in Bitcoin Treasury Giant Strategy
Binance Russia Data Case Highlights Crypto Exchanges’ Role in Law Enforcement
Binance Russia Data Case Highlights Crypto Exchanges’ Role in Law Enforcement
Bitpanda Fined €70K by Austria’s FMA Over MiCA Breaches
Bitpanda Fined €70K by Austria’s FMA Over MiCA Breaches
Hyperliquid’s HYPE Token Climbs Toward Key Resistance as Bulls Eye $77 Breakout
Hyperliquid’s HYPE Token Climbs Toward Key Resistance as Bulls Eye $77 Breakout
Vitalik Buterin Credits Bitcoin’s UTXO Ideas as Ethereum Explores Hyperscaling
Vitalik Buterin Credits Bitcoin’s UTXO Ideas as Ethereum Explores Hyperscaling

Find Us on Socials

You may also like

ICE Gave Vendors Six Days to Prove They Could Match TRM Labs

ICE Gave Vendors Six Days to Prove They Could Match TRM Labs

Crypto Week Ahead FOMC, White House Meet & Wyoming Symposium

Crypto Week Ahead: FOMC, White House Meet & Wyoming Symposium

Binance-Backed SafePal Data Leak Sparks Phishing Fears for 40K Buyers

Binance-Backed SafePal Data Leak Sparks Phishing Fears for 40K Buyers

Bitcoin Falls 47% in a Year, Saylor Reveals STRC Up 9% and STRK Down 27%

Bitcoin Falls 47% in a Year, Saylor Reveals STRC Up 9% and STRK Down 27%

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information