CryptoMag
NEWS Published: AUG 18, 2026, 1:02 PM

Apple Fixes Critical macOS Vulnerability Used for Monero Mining

Critical macOS Vulnerability Patched by Apple

Apple has addressed a significant macOS flaw that was exploited to install Monero mining software on compromised devices. The vulnerability, tracked as CVE-2026-65400, allowed attackers to gain root access to Macs by targeting the Screen Sharing service. The issue was confirmed by the Netherlands’ National Cyber Security Centre (NCSC), which reported that attackers were able to remotely install mining software on internet-facing Macs.

Details of the Vulnerability

The NCSC’s advisory highlighted that typically secure systems with port 5900 exposed to the internet were particularly vulnerable. Dutch cybersecurity officials stated that the macOS flaw allows unauthorized access and installation of Monero miners after exploiting the Screen Sharing services. According to experts from Huntress, tens of thousands of Macs might have been exposed due to these vulnerabilities, especially those that are internet-hosted.

Security Updates Required

Apple released the patch for this flaw in macOS updates on August 6 across various versions including Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Users are urged to install these updates immediately, as simply changing Screen Sharing passwords will not mitigate the risk. The flaw has been rated as 9.8 critical by CISA, indicating its severity.

Impact of the Exploit

In instances of exploitation, attackers used compromised Macs for cryptojacking, utilizing their computing power to mine Monero. The NCSC has not disclosed the specific software used for the mining or any details about the attackers. However, it emphasized that no theft of wallet credentials was reported.

Recommendations for Users

Cybersecurity analysts recommend that all users with potentially vulnerable Macs should update their systems promptly. Despite any assumptions about the disabled status of the Screen Sharing service, it is advised to install the security updates as malicious actors may find ways around these settings.

Conclusion

The urgency conveyed by the NCSC and Huntress highlights the critical nature of this vulnerability and the importance of timely security updates for macOS users. Further details regarding the extent of the attacks or the identities of the attackers may be disclosed by cybersecurity officials in the future.

Source: crypto.news

XMR / ZAR

Monero · Rank #24

R7,945.69

+5.68% 24h

24h High
24h Low

7-day price

Chart data unavailable.

View full XMR market Trade

Powered By