{"id":2376,"date":"2026-08-17T16:53:59","date_gmt":"2026-08-17T16:53:59","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2376"},"modified":"2026-08-17T16:53:59","modified_gmt":"2026-08-17T16:53:59","slug":"apple-macos-screen-sharing-flaw-exploited-on-internet-exposed-macs-to-install-monero-miner","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2376","title":{"rendered":"Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjhudlXOxVGnImI0OoIDMwrIy0pc2zaf1aV0B4ga_QSrt5UPX5G_BJl76VvdEUxkxJ4pjopKLsohJrwVwBgS0a-xLJvW7ZvCPvG3ezz_5vY1ABYZnysPR-ZFvVlEXVdZkCWuuHp2IAra5N3IgH_Lf8wuwVF7hx4zYXf0qF7MyOC8M83ZpQVQ5jcjzbLP4Jq\/s1700-e365\/apple-screenshare.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has <a href=\"https:\/\/advisories.ncsc.nl\/2026\/ncsc-2026-0280.html\" target=\"_blank\">warned<\/a>.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-65400\" target=\"_blank\">CVE-2026-65400<\/a><\/strong> (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials.<\/p>\n<p>The updates released by Apple improve state management mechanisms to enforce correct credential validation and prevent unauthorized authentication attempts. The shortcoming was addressed as part of an emergency update in <a href=\"https:\/\/support.apple.com\/en-us\/148170\" target=\"_blank\">macOS Tahoe 26.6.1<\/a>, <a href=\"https:\/\/support.apple.com\/en-us\/148171\" target=\"_blank\">macOS Sequoia 15.7.9<\/a>, and <a href=\"https:\/\/support.apple.com\/en-us\/148172\" target=\"_blank\">macOS Sonoma 14.8.9<\/a> earlier this month.<\/p>\n<p>\u00abAn authentication issue was addressed with improved state management,\u00bb Apple said in an advisory released on August 6, 2026. It credited security researcher Alfredo Pesoli of Bynario for discovering and reporting the issue.<\/p>\n<p>In an update to its advisory, the NCSC-NL said it has received a report indicating active abuse of the vulnerability across multiple systems on which port 5900 was accessible from the internet.<\/p>\n<p>\u00abIn all these cases, root had gained access to the affected system and placed a Monero crypto miner,\u00bb the agency added.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>There are currently no details on when these attacks were observed, the scale of such efforts, if the flaw was exploited as a zero-day, and if it goes beyond cryptocurrency mining.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Calif, which published <a href=\"https:\/\/blog.calif.io\/p\/no-country-for-old-passwords\" target=\"_blank\">additional information<\/a> about the flaw, said it&#8217;s part of a series of bugs in the Screen Sharing Server component that were patched by Apple with <a href=\"https:\/\/support.apple.com\/en-us\/128067\" target=\"_blank\">macOS Tahoe 26.6<\/a> shipped late last month &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43779\" target=\"_blank\">CVE-2026-43779<\/a><\/strong> (CVSS score: 9.8) &#8211;  A logic issue that could allow an app to intercept network connections intended for another process<\/li>\n<li><strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43777\" target=\"_blank\">CVE-2026-43777<\/a> <\/strong>(CVSS score: 7.5) &#8211; An unspecified issue that could a remote attacker to cause a denial-of-service (DoS)<\/li>\n<li><strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43760\" target=\"_blank\">CVE-2026-43760<\/a><\/strong> (CVSS score: 8.6) &#8211; An access issue that could allow an app to access user-sensitive data<\/li>\n<\/ul>\n<p>In a technical breakdown published following the release of the patches, Pesoli described CVE-2026-43760 as a post authentication bug that requires the target Mac to have Screen Sharing or Remote Management enabled with \u00abVNC viewers may control screen with password\u00bb configured and the attacker is already in possession of that VNC password.<\/p>\n<p>The problem, the researcher noted, resides in a legacy Screen Sharing authentication path involving VNC password access that turns a file copy operation into protected file disclosure, arbitrary root file creation, and remote root command execution.<\/p>\n<p>\u00abAfter the VNC authentication step, we cross a boundary the password was never supposed to cross,\u00bb Pesoli <a href=\"https:\/\/bynar.io\/blog\/a-root-remote-command-execution-on-macos-with-m5-in-2026\" target=\"_blank\">explained<\/a>. \u00abA remote viewer can make macOS Screen Sharing read protected files as root.\u00bb<\/p>\n<p>\u00abIn the other direction, the viewer can create attacker-controlled files as root. We used that second primitive to install a valid sudoers policy and turn a file-copy operation into a remote root command execution (or an LPE).\u00bb<\/p>\n<p>However, a security researcher who goes by the online alias @osxreverser <a href=\"https:\/\/reverse.put.as\/2026\/07\/29\/its-a-pre-auth-stupid\/\" target=\"_blank\">said<\/a> the real issue is a <a href=\"https:\/\/warez.sl0p.foo\/apple-screensharing-rce\/\" target=\"_blank\">pre-authentication vulnerability<\/a> in the Screen Sharing daemon (\u00abscreensharingd\u00bb) that makes it possible to pwn any Mac that has Screen Sharing enabled without having to know the password or anything else. The only prerequisite is knowing the IP address.<\/p>\n<p>The researcher also noted that they had been sitting on the bug \u00abfor a while\u00bb and that they did not report the issue to Apple \u00abgiven my long history with them.\u00bb<\/p>\n<p>\u00abMy last scan shown around 40k open screen sharing hosts on the internet, almost half in the U.S., most are residential IPs but there are many juicy hosts in Murican universities, some companies, a server from BBEdit company,\u00bb @osxreverser <a href=\"https:\/\/x.com\/osxreverser\/status\/2086090322459730169\" target=\"_blank\">said<\/a> in a subsequent post on X. \u00abParty hard, never expose those services unless behind SSH.\u00bb<\/p>\n<p>It&#8217;s worth noting that CVE-2026-65400 is distinct from the pre-auth vulnerability highlighted by @osxreverser, the latter of which was fixed by the tech giant in macOS 26.6 itself along with the other three flaws. What&#8217;s interesting here is that both of them reside in the same source code file, per Calif &#8211;<\/p>\n<p><em>@osxreverser&#8217;s bug is a single wrong return. A length check bails out early on an oversized frame and hands back a value that happens to be the success code from the read just before it. The caller reads that as \u00abthis auth step passed\u00bb and advances the state machine. Where the first bug is a stale return value, the second is a state machine desync.<\/em><\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p><em>Naming an account is the one thing the second bug needs, which makes it weaker than the first. It is not much of a barrier. A username is not a secret, and macOS prints them on the login window. The first bug does not even need that. The second bug was present in 26.5.2 too, sitting next to the first one the whole time.<\/em><\/p>\n<p><em>Both are logic bugs. There is no heap groom, no ASLR defeat, no race to win, no crash. Send one or two packets in the right order, and the target Mac machine lets you in. It works the first time, and it works every time, on every unpatched machine with Screen Sharing enabled.<\/em><\/p>\n<p>Calif said it&#8217;s withholding additional specifics about CVE-2026-65400 until a majority of users are upgraded with a fix, given the ease with which the exploits can be devised for the two pre-auth remote root using an artificial intelligence (AI) agent. The AI security company revealed it came up with a working exploit for both flaws in four hours.<\/p>\n<p>With CVE-2026-65400 now under active attack, the findings once again demonstrate how AI is collapsing the gap between vulnerability discovery and weaponization.<\/p>\n<p>Users are recommended to update their systems to the latest version for optimal protection. If immediate patching of the flaw is not possible, it&#8217;s advised to turn off Screen Sharing by navigating to General &gt; Sharing &gt; Toggle Screen Sharing from \u00abContent &amp; Media.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2377,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[618,128,70,1779,1113,421,3027,859,2265,939,3026],"class_list":["post-2376","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-apple","tag-exploited","tag-flaw","tag-install","tag-internetexposed","tag-macos","tag-macs","tag-miner","tag-monero","tag-screen","tag-sharing"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2376","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2376"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2376\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2377"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2376"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2376"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2376"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}