The vulnerability, tracked as CVE-2026-65400, stems from improper state management within the Secure Remote Password authentication process. By bypassing standard credentials, attackers could gain privileged control over exposed machines. Research from Huntress suggests that tens of thousands of Macs—particularly bare-metal systems hosted in data centers—were potentially vulnerable due to internet-facing port 5900.
In section Cryptocurrency
Apple Patches macOS Screen Sharing Flaw Exploited for Cryptojacking
Attackers have exploited a critical authentication vulnerability in macOS Screen Sharing, gaining root access to remotely install Monero mining software. The Netherlands’ National Cyber Security Centre confirmed active exploitation of the flaw, which has since been upgraded to a 9.8 critical severity rating by CISA.
Apple released security updates on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to resolve the issue. Experts emphasize that simple password changes or disabling legacy VNC authentication are insufficient to mitigate the risk. Because the exploit occurs prior to standard authentication protocols, users must install the latest system patches or disable the Screen Sharing service entirely until updates are applied.
Comments (0)
No comments yet. Be the first!