Cybersecurity

Mac vulnerability under active exploitation installs crypto miners

Published Aug 14, 2026, 6:46 PM1 min readNewUJ Editorial Desk

Mac vulnerability under active exploitation installs crypto miners
Photo: Kevin Horvat · Unsplash
0 0
XWhatsAppTelegramLinkedIn

Attackers are actively exploiting a high-severity macOS vulnerability that lets them execute malicious code, the Netherlands National Cyber Security Centrum (NCSC) warned. The flaw, tracked as CVE-2026-65400, was patched by Apple on August 7, 2026 for macOS Tahoe, Sequoia, and Sonoma; unpatched systems remain at risk.

The NCSC said it observed the attacks on multiple systems where port 5900 was accessible from the internet. In every observed case, attackers gained root access and installed a Monero crypto miner, which harnesses the Mac's resources to generate cryptocurrency.

Rated 7.1 out of 10, the vulnerability stems from a state management bug in macOS screen sharing, a feature that lets a remote party view and control the machine. Apple said the flaw "may" allow an attacker without credentials to gain access to a Mac.

Details of the vulnerability became public at the Black Hat security conference in early August 2026. Security practitioners advise keeping port 5900 closed; the macOS firewall opens it when screen sharing is enabled, and routers generally block it unless configured otherwise. They recommend using a VPN or SSH tunnel instead, though these options are beyond the capabilities of most users.

The safest practice is to disable screen sharing when it is not needed and enable it only for active sessions. Users can toggle screen sharing in System Settings > General > Sharing. Installing Apple's security update is essential. As of August 14, 2026, there were no indications the exploits had installed anything other than Monero miners, but attackers could use the flaw to deploy credential-stealing malware or other harmful code.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.