Hackers Are Turning Macs Into Crypto Miners Through This macOS Bug

A new flaw in Mac’s Screen Sharing tool is being exploited by hackers to take control of systems, steal sensitive data, and install malware.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

The Screen Sharing tool on macOS is no longer a harmless way to remotely control your Mac and access its screen as if you were sitting right in front of it. Researchers have found a new vulnerability in the tool that lets an attacker control your screen, keyboard, and mouse.[1]

Once the attacker gains control of your system, they could use it to interact with anything visible on the screen, steal saved passwords, sensitive personal data, browser sessions, and logged-in account details, install further spyware or ransomware, or establish a persistent backdoor on your system.

Luckily, Apple already released a fix to this a few weeks back[2] — although at the time, these macOS security updates were optional. But with new instances of the flaw being exploited by hackers, updating is now non-negotiable.

Here’s everything you need to know about this Mac vulnerability, why it’s a security gap you need to immediately close, and the steps you can take to protect yourself.

In this article
How this macOS Screen Sharing flaw can be exploited
What can you do to protect yourself
Bottom line

How this macOS Screen Sharing flaw can be exploited

When the vulnerability was first discovered, security researchers didn’t find any instances of attackers exploiting it.

However, a new advisory from the NeNational Cyber Security Centrum (NCSC), Netherlands, has revealed that the bug is now being actively exploited in the wild.

When Screen Sharing is enabled, the macOS firewall opens port 5900, making it accessible over the internet. Port 5900 is the default Transmission Control Protocol (TCP) port used by Virtual Network Computing (VNC), which is a protocol for remote desktop access.

Essentially, this lets one computer view and control another’s screen, keyboard, and mouse remotely.

By default, most home routers and firewalls block inbound connections to port 5900 from the public internet. But if it’s exposed — as is possible with this vulnerability — it could be abused by anyone on the internet.

Tracked as CVE-2026-65400, attackers are using this bug to install Monero miners — a cryptocurrency miner — on victims’ systems. These miners secretly hijack the victim’s computing resources to generate cryptocurrency for the attacker, causing significant system slowdowns and increased power consumption.

While researchers haven’t observed other forms of system compromise, an internet-facing port 5900 could allow an attacker to gain complete control of your system. This could open up a world of possibility:

  1. Just as easily as attackers are installing the miner, they could install spyware, ransomware, or other malware on your computer that could continuously exfiltrate sensitive personally identifiable information.
  2. Because the attacker can view a victim’s screen, they could also directly intercept any sensitive documents, emails, or messages visible on the screen, including two-factor authentication (2FA) codes. They could then steal browser sessions and credentials for any logged-in accounts, such as your banking or social media accounts.
  3. Attackers could even open applications, browse your file system, and harvest data from your Mac PC.
  4. The NCSC advisory also observed that attackers gained root access during these attacks, which means that they’re well capable of gaining full administrative control over the device’s operating system.
  5. Root access also means attackers could create hidden user accounts or add their own SSH keys, giving them a backdoor into the system even if the Monero miner is found and removed. A surface-level cleanup might not be enough to close this backdoor.

What can you do to protect yourself

Although the vulnerability is capable of causing significant damage, including allowing hackers to use your sensitive data to launch phishing attacks for identity theft or financial fraud, there are still some steps you can take to fix this security loophole.

  1. Install Apple’s update: Apple has already released patches for macOS Tahoe, Sequoia, and Sonoma. Since there was no known exploitation earlier, the update seemed more or less optional. But now, with cases of threat actors exploiting the vulnerability against victims, updating your macOS software has become a necessity.
  2. Use a virtual private network (VPN): A VPN can help keep port 5900 from being exposed directly to the public internet. Instead of forwarding port 5900 through your router and making it accessible to anyone online, you can keep it closed to the public internet and make Screen Sharing reachable only to devices that have authenticated into your private network through the VPN.
  3. Use Screen Sharing only when needed: Screen Sharing on macOS isn’t enabled out of the box. A user has to explicitly turn it on. So, users who have turned it on at some point and forgotten about it are more susceptible to this vulnerability. As a safe practice, toggle Screen Sharing only when you need it. Enable it before a session, complete the work, and then disable it again. You can also micromanage which users or administrators are allowed to connect through Screen Sharing, which further reduces the risk.
  4. Use a third-party antivirus program: If you suspect that you’ve already been impacted by this vulnerability, using an antivirus program can help you mitigate the threats. Antivirus tools come with signature-based and behavioral detection engines that can scan for known crypto miners like Monero miners. Additionally, they’re capable of detecting sudden spikes in resource usage or unexpected outbound network connections. However, it’s worth noting that antivirus is primarily a post-exploitation protection measure here and cannot be relied upon to prevent the initial exploitation of the Screen Sharing vulnerability.

Bottom line

The new macOS Screen Sharing bug could allow an attacker to access your screen, keyboard, and mouse and potentially steal everything on your system, including your passwords, login credentials, and personally identifiable information.

However, the good news is that Apple has already shipped patches for the vulnerability for macOS Tahoe, Sequoia, and Sonoma. So, there’s a simple way to close this security gap and protect yourself.

However, if you’re on an older macOS version, ensure that you enable Screen Sharing only when needed, and even then, avoid exposing port 5900 directly to the internet and use a VPN to route your connections instead. Additionally, you could use a third-party antivirus to detect and remove any existing infections.

#1 Rated VPN for Privacy and Security
5.0
Editorial Rating
Get Deal
On NordVPN's website
2026 Editors’ Choice
Best Overall VPN
VPN
NordVPN
PROMOTION: Get 75% Off + 3 Months Extra
  • Our #1 rated VPN, which has increased download speeds by up to 36% across all regions in our testing
  • Historically unlocks Netflix libraries in the US, Canada, UK, and Australia with no errors
  • Bundles with ad blocker, data removal, and encrypted storage for a more complete privacy setup

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Vulnerability giving attackers full control of Macs is under active exploitation

[2] Apple security releases