Vulnerability in Mac Allowed Installation of Hidden Monero Miners

cryptonews.ruPublished on 2026-08-17Last updated on 2026-08-17

Abstract

The Dutch National Cyber Security Centre (NCSC) identified a new attack vector targeting Mac devices, exploiting a vulnerability in the Screen Sharing feature. This flaw allowed attackers to gain complete control of a computer, steal data, and install a Monero cryptocurrency miner. Details regarding the number of victims or attackers were not disclosed. The NCSC issued a report on August 12. Initially, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) assigned the threat (CVE-2026-65400) a risk rating of 7.1 out of 10, but raised it to 9.8 two days later. Apple has since patched the vulnerability in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company, the bug could allow unauthorized remote access to a Mac via Screen Sharing. While this feature is disabled by default, it is frequently enabled for remote access, including to Apple devices via remote servers. Researcher Ryan Doud from Huntress urged macOS users to install the latest updates immediately, noting that a scan via Censys revealed tens of thousands of potentially vulnerable hosts.

The Dutch National Cyber Security Centre (NCSC) detected a new vector of online attacks on Mac devices via a vulnerability in Screen Sharing.

The NCSC reported that attackers gained full control of the computer, stole data, and installed a Monero miner. The number of victims and suspected participants in the attacks was not disclosed.

The organization released a report on the vulnerability on August 12. At that time, the U.S. Cybersecurity and Infrastructure Security Agency assigned the threat CVE-2026-65400 a risk rating of 7.1 out of 10, but raised it to 9.8 two days later.

Source: U.S. Cybersecurity and Infrastructure Security Agency.

Apple has already fixed the bug in an update for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to the company's description, due to this bug, an attacker could gain access to a Mac via Screen Sharing without authorization.

The "Screen Sharing" function is disabled by default, but it is often enabled for remote access to Apple devices, including via remote servers.

Huntress researcher Ryan Daud urged macOS users to install the latest updates immediately. According to him, a search via Censys revealed tens of thousands of potentially vulnerable hosts.

Recall that in May, the AI model Claude Mythos helped "white-hat" hackers hack macOS. Researchers were able to bypass Apple's Memory Integrity Enforcement protection mechanism.

end-content

Related Questions

QWhat is the vulnerability in Mac that allowed hidden Monero miners to be installed?

AThe vulnerability was in the Screen Sharing feature, which allowed attackers to gain unauthorized access to a Mac computer.

QWhich agency initially gave the threat a risk rating of 7.1 out of 10, and what was it later raised to?

AThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) initially gave it a rating of 7.1. Two days later, it raised the rating to 9.8 out of 10.

QWhich macOS versions received updates from Apple to fix the Screen Sharing vulnerability?

AApple fixed the bug in updates for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.

QHow many potentially vulnerable hosts were discovered through a search on Censys according to researcher Ryan Daught?

AA search via Censys revealed tens of thousands of potentially vulnerable hosts.

QIn a previous security event mentioned, what did the AI model Claude Mythos help 'white hat' hackers bypass?

AThe AI model Claude Mythos helped 'white hat' hackers bypass Apple's Memory Integrity Enforcement mechanism.

Related Reads

Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

Hardware crypto wallet manufacturer SafePal has disclosed a data breach affecting approximately 39,798 users. On August 16, the company announced that leaked information includes customer names, delivery addresses, phone numbers, email addresses, and order details. However, sensitive data such as seed phrases, private keys, passwords, bank details, and card numbers were not compromised, as SafePal states it does not collect or store this information. An internal investigation found no evidence that attackers accessed user wallets or funds. The primary risk for affected customers is targeted social engineering attacks. Scammers may use the leaked order details to pose as customer support, offering fake refunds, urging firmware updates, or sending phishing links. SafePal is monitoring and taking down such fraudulent sites and warns users to be cautious of any communication referencing their order information. The breach originated from an authorization vulnerability in a third-party order-tracking plugin, which allowed unauthorized access to other customers' order data. The issue affected orders placed between March 2, 2025, and April 11, 2026. The company has since patched the vulnerability and strengthened its system protections. In response, SafePal is conducting a joint investigation with an independent security firm and auditing its entire order processing system. Additional measures include reducing data retention in the affected system to 90 days and notifying logistics partners. While user crypto assets remain secure, the incident highlights a recurring pattern in the industry where breaches of customer data from hardware wallet companies lead to sophisticated phishing campaigns, similar to past incidents involving Ledger and Trezor. The vulnerability underscores that security risks often lie not in the wallet's cryptography but in auxiliary web services and third-party integrations.

cryptonews.ru29m ago

Data of Almost 40,000 SafePal Hardware Wallet Users Exposed to Third Parties

cryptonews.ru29m ago

Curve Founder Calls pump.fun a 'Casino with Scams' and Criticizes Phantom

Curve Finance founder Mikhail Egorov criticized the Solana ecosystem, calling the pump.fun platform a "casino with scams under the name of memecoins" and the Phantom wallet inconvenient to use. Egorov stated that pump.fun is essentially a casino of memecoin scams. He also negatively assessed Phantom's user experience, describing issues while trying to connect it to a hardware wallet and calling its UX worse than MetaMask's. However, he acknowledged that Solana does a very good job of supporting its ecosystem, though he added that its best examples are "not very good." An X user disagreed with the criticism of pump.fun, arguing the platform merely provides a tool and users decide how to use it, noting a large part of the crypto market operates like a casino on various blockchains. Regarding Phantom, the user suggested it might be one of the best options for average users despite personal non-use. In response, Egorov compared the situation to a common software pattern where initial quality and user support can later lead to developer "laziness" and product deterioration, a phenomenon he observed in both the Ethereum ecosystem and beyond. When asked about his favorite crypto wallet, Egorov named qeth, a project he developed himself using Claude AI. His motivation was dissatisfaction with JavaScript-based wallets, which he felt excessively burdened his laptop and drained its battery.

cryptonews.ru31m ago

Curve Founder Calls pump.fun a 'Casino with Scams' and Criticizes Phantom

cryptonews.ru31m ago

Trading

Spot
活动图片