[tooling] · · 2 min read
Active exploitation of macOS screen sharing flaw exposes Macs to crypto miners
Dutch cyber authorities confirm active abuse of a high-severity vulnerability in macOS screen sharing that allows unauthenticated remote code execution and root access.
By ByteBulletin Editors · Editorial Team
Dutch national security officials have issued a warning that a high-severity vulnerability in macOS is under active exploitation, resulting in the deployment of cryptocurrency miners on affected systems. The flaw, identified as CVE-2026-65400, stems from a bug in the operating system's screen sharing capability, specifically within its state management logic. This allows a remote attacker to execute malicious code, gain root access, and install payloads without requiring valid user credentials.
The Netherlands National Cyber Security Centrum (NCSC) noted that in all observed cases of active abuse, the vulnerability was triggered when port 5900 was accessible from the internet. This port is opened by the macOS firewall when screen sharing is enabled. While routers and dedicated firewalls typically block this port by default, misconfigurations or users who explicitly enable screen sharing for remote work can inadvertently expose their machines to the internet. The attackers have so far been observed installing Monero crypto miners, which surreptitiously use the Mac's processing power to generate cryptocurrency for the adversary.
Apple released a patch for this vulnerability last week, covering macOS Tahoe, Sequoia, and Sonoma. The issue was disclosed at the Black Hat security conference, with credit given to security firm Bynario for reporting the bug. Apple described the vulnerability as potentially allowing an attacker without credentials to gain access to a Mac, a description that security experts note is consistent with the severity rating of 7.1 out of 10.
For developers and technical users, the primary mitigation is to ensure the latest security updates are installed. However, configuration hygiene is also critical. Security practitioners advise keeping port 5900 closed even when screen sharing is needed, recommending the use of VPNs or SSH tunneling for remote access instead. For general users, the safest practice is to disable screen sharing in System Settings > General > Sharing unless it is actively required, and to turn it off immediately after a session ends. Although current exploitation is limited to crypto mining, the potential for more malicious payloads, such as credential stealers or persistent malware, remains a significant risk for unpatched systems.
SHARE
RELATED
[tooling] ·
Agentic Ship: An Open-Source Toolkit to Replace Hosted AI Builders
A new MIT-licensed toolkit provides the rules, gates, and backend conventions of platforms like Lovable and Bolt, but runs locally within your existing coding agent.
[tooling] ·
Hexis: A Git-Backed Control Plane for Managing AI Agent Skills and Permissions
Bevel Software releases Hexis, an open-source tool that treats AI agent skills and tools as version-controlled files with granular access control and bidirectional review capabilities.

[tooling] ·
Cline Desktop Accelerates Release Cadence in Latest Iterations
Recent updates to the Cline desktop application signal a push toward stability and feature refinement in the AI coding assistant space.