Apple Screen Sharing Flaw Lets Anyone Take Over Macs and Mine Monero
The myth of unhackable computers takes another hilarious hit as a built-in remote desktop toggle silently turns sleek machines into automated cryptocurrency mining rigs with zero login credentials required.
When the built-in Screen Sharing tool in macOS is toggled on, the operating system quietly punches port 5900 straight through the local firewall. Attackers discovered they could completely bypass authentication via CVE-2026-65400 and seize root-level control, instantly transforming high-end workstations into unpaid laborers mining Monero.
The threat was flagged in the wild by the National Cyber Security Centre of the Netherlands after noticing automated intrusions hitting exposed systems. Apple issued an out-of-band security update across macOS Sequoia, Sonoma, and Tahoe, but the official danger assessment took days to catch up to reality.
While the United States CISA initially tagged the flaw with a modest 7.1 severity score, the agency quickly upgraded the vulnerability to a near-maximum 9.8 CVSS rating upon discovering that the attack requires zero privileges and executes entirely over the network. Technical mechanics revealed at the Black Hat conference linked the arbitrary root takeover directly to memory corruption techniques previously showcased against Apple M5 silicon.
The age-old belief that premium hardware is immune to internet chaos continues to evaporate every time a default feature bypasses authentication. It appears that no amount of industrial design can protect a machine once an unauthenticated network door is left wide open to anyone with an internet connection.
Source: Calif
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.