Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
Overview
Hackers are exploiting a recently patched vulnerability in macOS, known as CVE-2026-65400, which allows unauthorized access to the macOS Screen Sharing feature. This flaw enables attackers to bypass authentication and gain root access to affected systems, leading to the installation of cryptominers without user consent. The Netherlands’ National Cyber Security Centre has issued a warning about this active exploitation, emphasizing the need for users to update their systems. Apple has released patches for macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1) to address this issue, urging all macOS users to upgrade promptly to protect their devices. Failure to do so could leave systems vulnerable to further attacks and unauthorized resource usage.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: macOS Sequoia (15.7.9), macOS Sonoma (14.8.9), macOS Tahoe (26.6.1), Apple macOS systems
- Action Required: Users should upgrade their macOS systems to the latest versions: Sequoia (15.
- Timeline: Newly disclosed
Original Article Summary
A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attackers authenticate to macOS Screen Sharing without valid login credentials. Apple fixed the issue with updates to macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1), and advised its macOS users to upgrade their systems. “An authentication … More → The post Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer appeared first on Help Net Security.
Impact
macOS Sequoia (15.7.9), macOS Sonoma (14.8.9), macOS Tahoe (26.6.1), Apple macOS systems
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should upgrade their macOS systems to the latest versions: Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1) to patch the vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to macOS, CVE, Apple, and 3 more.