The screen sharing flaw that Apple released a patch for earlier this month has already been wildly exploited, according to the Netherlands National Cyber Security Center (NCSC-NL).
On August 6, Apple released macOS Tahoe 26.6.1, an update to the macOS Tahoe operating system released last year. The update came just over a week after Apple released macOS Tahoe 26.6.
In its security support document, Apple said the update addresses a vulnerability that could allow an attacker to authenticate to Screen Sharing without valid credentials. In short, it allowed a malicious actor to view a user’s Mac screen and remotely take control of their keyboard and mouse. However, it seems that hackers have already taken advantage of this flaw.
As first reported ArsTechnicaNCSC-NL said it was informed of abuse of the vulnerability, “observed on several systems where port 5900 was accessible from the Internet.” The reason is that when screen sharing is enabled, the macOS firewall intentionally exposes this port.
“In all of these cases, root was gained on the affected system and a Monero crypto miner was placed,” the NCSC-NL added. In other words, the resources of a targeted Mac are used to mine cryptocurrency.
In offering the fix – which was also included in macOS Sonoma 14.8.9 and macOS Sequoia 15.7.9 – Apple said it fixed the authentication issue with “improved state management.” Users who have not updated their Mac should do so as soon as possible. Even for those who have updated, using a VPN is also recommended when screen sharing is active.
If you’re not sure whether your version of macOS is up to date, you can check by going to your Mac’s system settings and selecting General ➝ Software Update.
