Apple has patched a serious flaw in the Mac screen-sharing feature after attackers used it to seize control of exposed systems and quietly install Monero mining software. The issue was highlighted by the Netherlands’ National Cyber Security Centre, which said multiple internet-accessible Macs were compromised through the bug.
The vulnerability affected Apple’s built-in screen-sharing capability and could be triggered before a user authenticated. Because the attack path did not require a valid password, simply changing account credentials would not stop an active exploit if a device remained exposed.
Attackers abused pre-authentication access
According to the Dutch cyber agency, the flaw let hackers reach Macs over a network and obtain full control of affected machines. The compromised systems were then used to run Monero mining software without the owners’ knowledge.
The weakness was tied to screen sharing, a feature designed to let users access a Mac remotely. While the function is disabled by default, it is commonly enabled on remote servers and other systems that need off-site administration, which can make internet-exposed deployments a higher-risk target.
Researchers described how the flaw worked
The bug could be exploited without a valid password and before the normal authentication process completed. That made it unusually dangerous, since defenders could not rely on password resets alone to block an attacker who was already using the vulnerability.
Security firm Huntress said the exploit effectively tricks a Mac into recognizing an outside connection as if it were part of an already authenticated session. In practice, that allowed the attacker to bypass the expected login barrier and operate the device remotely.
Apple issued fixes across supported macOS versions
Apple addressed the vulnerability on August 6 through security updates for macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Microsoft researchers called on users to install the latest updates immediately.
The severity assessment also increased as more details emerged. The U.S. Cybersecurity and Infrastructure Security Agency initially scored the flaw at 7.1 out of 10, then later raised that rating to 9.8, reflecting a far more critical view of the risk.
Why Monero is often used in cryptojacking
The malware deployed in these attacks mined Monero, a cryptocurrency that has long been associated with cryptojacking campaigns. Attackers typically favor it because infected machines can be used to generate coins in the background while the victim absorbs the computing and electricity costs.
The Monero network currently produces about 432 XMR per day. For defenders, the immediate confirmed next step is straightforward: systems running the affected macOS versions need Apple’s latest patches, especially where screen sharing is enabled or machines are reachable from the public internet.
Source: en.bloomingbit.io