Cybersecurity & Digital Trust▲impact 4
Monero mining malware confirmed exploiting macOS screen sharing vulnerability
The National Cyber Security Centre of the Netherlands has confirmed that a vulnerability in Apple's macOS screen sharing feature has been actively exploited, with multiple Macs taken over and Monero cryptocurrency mining malware installed. All affected Macs had the screen sharing feature accessible over the internet, and attackers obtained administrator privileges before deploying Monero mining software. The issue stems from a flaw in macOS authentication handling that could allow network access to screen sharing without valid credentials. On August 6, Apple released fixes in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, improving authentication state management to prevent unauthorized authentication attempts. Security firm Huntress has analyzed the vulnerability as exploiting pre-authentication processing to treat third-party connections as legitimate users, meaning changing or removing the screen sharing password does not address the root cause. Huntress's investigation found tens of thousands of potentially affected hosts on the internet, and the company is urging all users of screen sharing to apply updates promptly. The US Cybersecurity and Infrastructure Security Agency has also raised the CVSS rating for this vulnerability from 7.1 to 9.8.