Dutch Cybersecurity Agency Sounds the Alarm
The Netherlands’ National Cyber Security Centre (NCSC-NL) issued an alert regarding active exploitation of a macOS Screen Sharing vulnerability. Threat actors have reportedly bypassed authentication on multiple internet-accessible Macs. In each instance, attackers achieved root-level access, then deployed Monero cryptocurrency mining software.
The Authentication Bypass Behind It All
The vulnerability, identified as CVE-2026-65400, allowed remote attackers to bypass authentication for Screen Sharing entirely. Apple released patches on August 6 covering three macOS versions:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
Screen Sharing is Apple’s built-in remote desktop feature, typically running the Remote Framebuffer protocol on TCP port 5900. It’s not enabled by default, but it shows up often on managed workstations and hosted servers, many of which expose port 5900 directly to the internet.
How Attackers Slipped Past Authentication
The flaw lives in macOS’s implementation of Secure Remote Password authentication within the screen sharing service. A technical analysis found an error in frame length validation that caused the service to return an outdated success status, even when it shouldn’t have.
As a result, the service could treat an unauthenticated connection as legitimate, letting attackers proceed without any real cryptographic verification. Apple fixed this by improving state management, according to its Sonoma security advisory.
Once connected, attackers could abuse Screen Sharing’s privileged file handling to read or create files with root level permissions. No valid macOS account or VNC password was required. The National Vulnerability Database assigned this flaw a critical CVSS score of 9.8.
What Root Access Actually Means Here
Cryptocurrency mining is really just the visible part of this. Root access hands attackers full control over the compromised system, including the ability to steal files and credentials, install additional backdoors, tamper with security tools, or use the Mac as a launchpad for further network attacks.
Victims might notice warning signs like high CPU usage, increased power consumption, or overheating, but the miner itself is just a symptom of a much deeper breach. NCSC-NL has not disclosed how many systems have been compromised so far.
What Mac Owners Should Do Right Now
Installing the latest macOS updates immediately is the only way to correct the underlying authentication flaw. This affects earlier builds of macOS Tahoe, Sequoia, and Sonoma.
Beyond patching, a few practical steps matter:
- Disable Screen Sharing if you’re not actively using it, through System Settings, General, then Sharing
- Organizations should restrict port 5900 access with a firewall or VPN
- Treat any Mac suspected of compromise as fully breached
For a suspected compromise, that last point means preserving evidence, erasing the device, and reinstalling macOS from a trusted source. All stored credentials and keys should be rotated from a separate, clean machine afterward.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



