Your Mac's screen sharing tool had a secret skip-the-password bug — and hackers used it to mine crypto

CVE-2026-65400 let anyone on the network log into a Mac as root with zero credentials. Apple patched it August 6. Attackers were already inside,…

Aliteq
Priya Nair · Software & Systems Editor

CVE-2026-65400 is an authentication bypass in macOS's Screen Sharing daemon (screensharingd) — a network attacker can log in as root with no valid credentials.

Apple originally scored it CVSS 7.1; after confirmed active exploitation, CISA rescored it to 9.8 (Critical) on August 14.

The flaw affects macOS Tahoe 26.5.2 and earlier, Sequoia 15.7.8 and earlier, and Sonoma 14.8.8 and earlier — patched in Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9, released August 6, 2026.

Attackers used root access to install the XMRig 6.26.0 cryptominer, disguised as a hidden .config/sysmond binary running via a LaunchDaemon.

Microsoft Defender and the Netherlands' NCSC-NL documented the campaign; researcher Alfredo Pesoli of Bynario is credited with the original discovery.

Who needs to act now

Anyone running Screen Sharing on a Mac reachable from an untrusted network — a home Mac with port forwarding, a Mac mini used as a remote-access server, or any machine on a network segment attackers…

Aliteq

Read the full story

Your Mac's screen sharing tool had a secret skip-the-password bug — and hackers used it to mine crypto

Read the full story on Aliteq