Critical macOS Vulnerability Hijacked for Crypto Mining: What Miners and Mac Users Need to Know
A Newly Patched macOS Flaw Is Already Being Exploited Apple users are being urged to update their systems immediately after security researchers and the Netherlands National Cyber Security Centre (NCSC) confirmed active exploitation of a critical macOS Screen Sharing vulnerability. The flaw, tracked as CVE-2026-65400, is being used by attackers to gain unauthorized access to

A Newly Patched macOS Flaw Is Already Being Exploited
Apple users are being urged to update their systems immediately after security researchers and the Netherlands National Cyber Security Centre (NCSC) confirmed active exploitation of a critical macOS Screen Sharing vulnerability. The flaw, tracked as CVE-2026-65400, is being used by attackers to gain unauthorized access to vulnerable Macs and install Monero mining malware.
While cryptocurrency mining malware is nothing new, the speed at which attackers weaponized this vulnerability highlights an ongoing trend: cybercriminals continue to favor crypto mining operations as a low-risk, highly scalable source of revenue.
How the Attack Works
The vulnerability affects Apple’s built-in Screen Sharing service, which allows remote desktop access over the VNC protocol. Researchers found that attackers could bypass authentication mechanisms and gain access to systems exposing TCP port 5900 to the internet. In many reported cases, the attackers were able to escalate privileges to root access before deploying malware.
Unlike many attacks that rely on phishing emails or stolen credentials, this exploit can be carried out remotely against improperly exposed systems. That significantly lowers the barrier for attackers scanning the internet for vulnerable Macs.
Why Monero?
The malware being deployed is primarily focused on mining Monero (XMR), a privacy-focused cryptocurrency that has long been favored in illicit mining campaigns. Unlike Bitcoin, Monero is designed to be mined efficiently on consumer hardware, making it a natural choice for attackers looking to monetize compromised computers.
For cybercriminals, Monero offers several advantages:
- CPU-friendly mining compared to Bitcoin ASIC mining.
- Privacy-focused transactions that are difficult to trace.
- Ability to generate ongoing revenue from compromised devices.
- Lower operational risk than ransomware attacks.
A single infected Mac may not generate substantial profits, but thousands of compromised systems operating around the clock can create a significant stream of passive income for attackers.
The Bigger Picture for Crypto Mining
Although the Endless Mining community primarily focuses on legitimate mining operations, incidents like this reinforce an important reality: cryptocurrency remains valuable enough that attackers continue searching for new ways to acquire hash power.
The economics are straightforward. Instead of purchasing hardware, paying for electricity, and managing infrastructure, attackers attempt to offload those costs onto unsuspecting users. Every compromised machine effectively becomes a tiny mining node generating revenue for someone else.
This isn’t a threat exclusive to Mac users. Over the years, cryptojacking campaigns have targeted Windows PCs, Linux servers, cloud infrastructure, and even Internet of Things devices. The common denominator is simple: attackers follow profitability.
Who Is Most at Risk?
Current reports indicate that systems with Screen Sharing exposed directly to the internet are the primary targets. Organizations, remote workers, and advanced users who have enabled remote access without proper network protections face the highest risk.
Warning signs of infection may include:
- Unusually high CPU usage.
- Increased system temperatures.
- Constant fan activity.
- Reduced battery life on laptops.
- Sluggish overall performance.
- Unexpected network traffic.
Because mining malware is designed to remain active for extended periods, victims may not immediately realize their systems have been compromised.
How to Protect Your Mac
Apple has already released patches for affected systems. Security researchers recommend updating immediately to the latest available versions of macOS. The patched releases include:
- macOS Tahoe 26.6.1
- macOS Sequoia 15.7.9
- macOS Sonoma 14.8.9
Additional security measures include:
- Disable Screen Sharing if it is not required.
- Avoid exposing port 5900 directly to the internet.
- Use VPN access for remote connections whenever possible.
- Enable automatic security updates.
- Monitor systems for unusual CPU utilization or mining activity.
Final Thoughts
The rapid exploitation of CVE-2026-65400 demonstrates how quickly attackers move when new vulnerabilities emerge. Within days of Apple’s patch release, reports surfaced of compromised Macs being converted into Monero mining machines.
For miners, this serves as another reminder that security is just as important as hash rate. Whether you’re operating ASICs, managing GPU rigs, or simply using a Mac for day-to-day work, keeping systems patched and limiting unnecessary network exposure remains one of the most effective defenses against cryptojacking attacks.
In the race for computational power, attackers are constantly searching for someone else’s hardware to mine with. Don’t let your devices become part of their operation.