In Brief:
- Hackers exploited Apple’s Screen Sharing vulnerability to control internet-facing Macs and install Monero mining software without requiring valid user passwords.
- Apple patched the vulnerability across supported macOS versions, while its severity rating increased significantly from 7.1 to 9.8 points.
- Monero remains attractive for cryptojacking because ordinary computers can mine XMR, while its privacy features offer attackers greater transaction anonymity.
Hackers have exploited a vulnerability in Apple’s Screen Sharing feature to control Macs and install Monero mining software without authorization. Several affected computers were accessible through the internet, giving attackers an entry point for complete system takeover.
The Netherlands’ National Cyber Security Centre reported the attacks through an updated security advisory. The agency received reports involving multiple Macs where attackers installed software designed to mine Monero, also known as XMR.
However, the NCSC did not disclose the number of compromised computers or identify those responsible for the campaign. Apple has already released security updates addressing the vulnerability across several supported versions of macOS.
The company patched the flaw on August 6 in macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Apple explained that network attackers could access vulnerable Macs through Screen Sharing without supplying a valid password.
Screen Sharing allows users to remotely view and control their Macs from another computer. Although disabled by default, operators commonly enable the feature on bare-metal Apple machines hosted on remote servers.
Also Read: 5 Reasons People May Buy Cryptocurrencies
Authentication Bypass Leaves Internet-Facing Macs Exposed
Security firm Huntress found that the vulnerability affects the authentication process protecting Screen Sharing connections. Essentially, the flaw can make a Mac recognize an unauthorized connection as one belonging to an authenticated user.
Consequently, changing or deleting Screen Sharing passwords cannot prevent exploitation on an unpatched device. Huntress researcher Ryan Dowd urged users relying on Screen Sharing to install Apple’s latest security updates immediately.
Additionally, Dowd identified tens of thousands of potentially vulnerable hosts during a Censys search. That finding suggests the potential exposure extends beyond the Macs already identified in confirmed attacks.
Federal cybersecurity officials have also raised their assessment of the vulnerability’s severity. CISA initially rated the flaw 7.1 out of 10 when Apple released the security fix.
However, the National Vulnerability Database later recorded a 9.8 rating, placing the flaw near the maximum severity level. Despite reports of exploitation, it has not entered the federal catalog of vulnerabilities known to face active attacks.
Monero Mining Remains Attractive to Cryptojackers
Monero has frequently appeared in cryptojacking campaigns because miners can generate XMR using ordinary computers. Moreover, the cryptocurrency emphasizes transaction privacy, making it attractive to attackers seeking less transparent cryptocurrency payments.
Individual compromised machines generate relatively small returns because miners compete for the network’s available rewards. The Monero network distributes approximately 432 XMR daily among participating miners. Those rewards were worth roughly $179,000 at Sunday’s market price. Meanwhile, XMR traded near $415.82, representing an increase of approximately 3.7% over 24 hours.
The attacks demonstrate the security risks surrounding internet-accessible remote management services running outdated software. Installing Apple’s patched macOS releases removes the Screen Sharing vulnerability exploited in the reported Monero mining attacks.
Also Read: Ethereum Eyes $3,000 as Analyst Spots Repeat Rally From $1,580 Support
