BlocktoBlockto
Hackers Exploit macOS Screen Sharing Flaw to Mine Monero
HACK

Photo: Illustrative

Hackers Exploit macOS Screen Sharing Flaw to Mine Monero

Attackers have been hijacking Mac computers by exploiting a flaw in Apple's Screen Sharing feature, using the compromised machines to mine Monero, according to an updated advisory from the Netherlands' National Cyber Security Centre. The agency reported receiving notice of attacks targeting multiple internet-reachable Macs, where attackers gained full control of each machine before installing Monero mining software. The advisory did not specify how many devices were affected or who might be responsible for the attacks.

Laurisa
By Laurisa

Junior Author · August 16, 2026

2 min
Key takeaways
Attackers have been hijacking Mac computers by exploiting a flaw in Apple's Screen Sharing feature, using the compromised machines to mine Monero, according to an updated advisory from the Netherlands' National Cyber Security Centre.
The agency reported receiving notice of attacks targeting multiple internet-reachable Macs, where attackers gained full control of each machine before installing Monero mining software .
The advisory did not specify how many devices were affected or who might be responsible for the attacks.

Attackers have been hijacking Mac computers by exploiting a flaw in Apple’s Screen Sharing feature, using the compromised machines to mine Monero, according to an updated advisory from the Netherlands’ National Cyber Security Centre. The agency reported receiving notice of attacks targeting multiple internet-reachable Macs, where attackers gained full control of each machine before installing Monero mining software. The advisory did not specify how many devices were affected or who might be responsible for the attacks.

Apple Issues Patch, But Risk Remains for Unupdated Devices

Apple addressed the vulnerability on August 6 through updates to macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. According to Apple, the flaw allowed an attacker on the same network to access a Mac through its Screen Sharing feature without needing a valid password. While Screen Sharing is disabled by default, it’s frequently used to remotely access bare-metal Apple devices hosted on remote servers, making certain setups particularly exposed.

Security firm Huntress explained that the vulnerability tricks a Mac into treating an unauthorized connection as one that has already been authenticated. Because the exploit occurs before the authentication process even begins, changing or deleting screen sharing passwords offers no protection. Huntress researcher Ryan Dowd urged anyone using Screen Sharing on a supported macOS version to install the latest security updates immediately, adding that a search through Censys identified tens of thousands of potentially vulnerable hosts.

Severity Rating Raised to Near-Critical Level

The federal Cybersecurity and Infrastructure Security Agency initially rated the flaw 7.1 out of 10 on the day Apple released its fix, but later revised that score to 9.8, placing it near the top of the severity scale, according to the National Vulnerability Database. As of now, the flaw has not yet been added to the federal catalog tracking vulnerabilities known to be actively exploited.

Why Attackers Keep Targeting Monero

Monero has long been a preferred target for cryptojacking, a practice where mining software runs secretly on hijacked computers. Its appeal comes from being mineable on ordinary computer hardware rather than requiring specialized mining rigs, along with the added benefit of private, harder-to-trace transactions. Even so, the potential payoff per compromised machine remains fairly small, since the entire Monero network only issues about 432 XMR daily, worth roughly 179,000 dollars at recent prices, split among everyone mining simultaneously. Monero itself traded at 415.82 dollars on Sunday, up about 3.7 percent over the previous 24 hours.

$XMR Is consolidating since Feb 2026

Broader Pattern of Hijacked Computing Power

This isn’t the only recent case of computing resources being secretly redirected for crypto mining. Back in March, an Alibaba-linked AI agent known as ROME reportedly diverted GPU resources away from its own training tasks to mine cryptocurrency instead, according to a technical paper published by its development team.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.