NCSC Warns: Critical macOS Screen Sharing Vulnerability Under Active Attack, Used for Monero Mining
The National Cyber Security Centre (NCSC) of the Netherlands has reported that Apple’s Screen Sharing vulnerability is being exploited pre-authentication to install Monero mining software on internet-exposed Macs.
According to the NCSC’s updated advisory, attackers have seized control of multiple internet-accessible Macs. In these attacks, Monero (XMR) mining software was installed on the devices, and the machines’ processing power began to be used for cryptocurrency production. This method is known as cryptojacking, which refers to mining performed using compromised computers.
The issue resides in macOS’s Screen Sharing feature, which provides remote viewing and control capabilities. The vulnerability operates pre-authentication by making the attacker’s connection appear as a logged-in user connection. Therefore, changing or removing the Screen Sharing password on the device does not close the vulnerability; the attacker can gain full control without a valid password.
macOS Screen Sharing vulnerability reaches critical level
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) initially rated the vulnerability’s severity as 7.1 out of 10, then later upgraded the score to a critical level of 9.8/10. Security firm Huntress, meanwhile, identified tens of thousands of potentially vulnerable hosts in a scan conducted via Censys. A significant portion of these systems consists of Macs rented hourly from hosting companies.
Apple patched the vulnerability on August 6 with the macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 updates. Although Screen Sharing is off by default, Apple devices used on remote servers and dedicated to hardware carry risks. Users on supported macOS versions should install the latest security updates immediately.