Bullish
macOS Screen Sharing Flaw Exploited for Root Access and XMR Mining
15:04
CVE-2026-65400 allows unauthenticated root access on exposed Macs. Attackers deploy XMR miners via port 5900. Apple patches released; users urged to update or disable sharing.
Woofun AI reports that attackers are actively exploiting CVE-2026-65400, a critical authentication flaw in macOS screen sharing, to compromise internet-exposed devices. The vulnerability, rated 9.8 on the CVSS scale, permits unauthorized root access without valid credentials, leading to the deployment of XMR mining software on infected systems. Apple has issued patches in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Security Affairs recommends immediate updates or disabling screen sharing to block port 5900 exposure.
WOOFUN AI
Impact Assessment · Quick Read
The active exploitation of this high-severity flaw highlights persistent risks in default-enabled remote access features. With root access granting full system control, the deployment of crypto-miners indicates a shift toward resource hijacking rather than data theft. Users with exposed port 5900 face immediate compromise risk until patched, potentially impacting device performance and network bandwidth.
Generated by WOOFUN AI · For reference only, not investment advice
Comments
No comments yet.