[REVISION HISTORY]
macOS Screen Sharing vulnerability exploitation
Updated 2 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-21 14:00 UTC → 2026-08-21 14:06 UTC ·
added
removed
A critical authentication vulnerability in macOS Screen Sharing, identified as CVE-2026-65400, is being actively exploited by threat actors to gain remote root access to affected systems. The flaw allows attackers to bypass password requirements due to errors in how the system manages login states, particularly when port 5900 is exposed to the internet. Security agencies and firms have noted that attackers are using this exploit for cryptojacking, specifically installing Monero (XMR) cryptocurrency mining software on compromised machines. The Dutch National Cyber Security Centre (NCSC) has confirmed real-world exploitation, and security firm Huntress reported finding tens of thousands of potentially vulnerable hosts. In response to the threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) upgraded the vulnerability’s severity score from 7.1 to a critical 9.8, noting that the exploit can be fully automated and requires no prior privileges. The vulnerability specifically involves the Screen Sharing service’s implementation of the Secure Remote Password (SRP) protocol. If System Integrity Protection (SIP) is disabled, attackers can execute arbitrary code with elevated privileges. Security researcher Alfredo Pesoli, CEO of Bynario, is credited with identifying the flaw through automated detection systems. Apple released emergency security updates on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 to address the issue. Users are urged to update their software immediately to mitigate the risk of cryptocurrency mining Trojans being installed via this flaw.
Versions
- 2026-08-21 14:06 UTC macOS Screen Sharing vulnerability exploitation
- 2026-08-21 14:00 UTC macOS Screen Sharing vulnerability exploitation
- 2026-08-19 01:32 UTC macOS Screen Sharing vulnerability exploitation
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.