Vulnerability

Critical macOS Screen Sharing Vulnerability Exploited to Deploy Monero Miners

FORTSECURE GLOBAL· 2026-08-17🛰 SecurityWeek
#macOS#Apple#Cryptojacking#Malware#Network Security

Threat actors are actively exploiting a macOS screen sharing flaw to gain root access and install cryptocurrency mining malware.

Security researchers have identified a surge in active exploitations targeting a recently disclosed vulnerability in the macOS Screen Sharing feature. This flaw allows attackers to bypass security restrictions and elevate their privileges to 'root' level, granting them total control over the infected machine. Once control is established, the primary objective observed in recent campaigns is the deployment of a Monero (XMR) miner, transforming high-performance Apple hardware into tools for illicit cryptocurrency generation, a practice commonly known as cryptojacking.

From Unauthorized Access to Resource Hijacking

The vulnerability stems from an improper handling of session credentials within the Screen Sharing protocol. By sending specially crafted packets to a vulnerable system, an attacker can initiate a session without valid credentials or exploit the process to gain administrative rights. Once the attacker gains root access, they typically install persistence mechanisms to ensure the mining software continues to run after reboots. While the immediate impact is a significant degradation in system performance and increased electricity costs, the level of access obtained means that threat actors could easily pivot to data exfiltration or the installation of ransomware at any moment.

FortSecure Practical Recommendations

To protect macOS environments from this exploit, administrators should take immediate action:

  1. Immediate Patching: Ensure all macOS devices are updated to the latest OS version. Apple has released security updates specifically addressing this flaw.
  2. Restrict Remote Management: Disable 'Screen Sharing' and 'Remote Management' in System Settings unless they are absolutely necessary for business operations. If required, limit access to specific IP addresses via a firewall.
  3. Implement EDR Solutions: Deploy Endpoint Detection and Response (EDR) tools that can identify the specific signatures of mining software and flag unusual spikes in CPU utilization.
  4. Strong Authentication: Enforce the use of strong, unique passwords and Multi-Factor Authentication (MFA) for all accounts with remote access capabilities.

แหล่งที่มา: SecurityWeek เผยแพร่ครั้งแรก: Mon, 17 Aug 2026 08:47:38 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: SecurityWeek

เผยแพร่ครั้งแรก: Mon, 17 Aug 2026 08:47:38 +0000

บทความต้นฉบับ: https://www.securityweek.com/recent-macos-screen-sharing-vulnerability-exploited-in-attacks/

อ่านบทความต้นฉบับ ↗

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog