EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Hackers exploit Apple screen sharing vulnerability to install Monero...

2026-08-18 00:13:17
Bookmark

How can an attacker control a vulnerable Mac?

The attacker used a key vulnerability in Apple's screen-sharing feature to take control of an Internet-accessible Mac computer and install Monero mining software. The Dutch National Cyber Security Center said it has received multiple reports involving Mac computers that can be accessed directly over the Internet. In each case, the attacker gained full control of the device before installing software designed to mine Monero, a privacy-conscious cryptocurrency coded XMR. The vulnerability affects Apple's screen-sharing feature, which allows one computer to remotely view and control another Mac. Although this feature is disabled by default, it is usually used with remotely hosted Apple hardware, including bare metal Macs rented from a hosting provider. Security researchers point out that the vulnerability allows attackers to make remote connections appear to have been authenticated. Because the vulnerability appears before the normal authentication process, changing or deleting the screen sharing password does not prevent the vulnerability from being exploited. Security firm Huntress said a search of Internet-connected systems found tens of thousands of potentially vulnerable hosts. Many of these machines appear to be Macs provided by hosting companies, and customers can rent Apple hardware remotely by the hour.

Which Macs need updates?

Apple fixed the vulnerability on August 6 by updating macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. If screen sharing is enabled and accessible from the Internet, Mac computers that do not have the latest security updates are still at risk. Apple said attackers on the same accessible network could gain access through screen sharing without providing a valid password. Huntress researcher Ryan Dowd urges all users using the feature on supported versions of macOS to install the latest security updates immediately. After the fix was released, the severity assessment of the vulnerability also increased significantly. U.S. cybersecurity authorities initially rated the vulnerability on a score of 7.1 out of 10, and later increased it to 9.8, close to the highest score in the universal vulnerability scoring system. Although Dutch agencies have reported attacks involving multiple systems, the vulnerability has not yet been included in the list of security vulnerabilities that the U.S. government has confirmed have been actively exploited.

Investor Highlights

This incident shows that cryptographic hijacking is still economically feasible when attackers are able to hack into a large number of machines at low cost. For hosting providers and businesses running remote Macs, the main financial risks may be higher computing costs, performance degradation, and broader network exposure, rather than the value of the cryptocurrency being mined itself.

Why do crypto hijackers prefer Monero?

Monero has long been used for crypto-hijacking activities because it can be efficiently mined on ordinary processors without relying on dedicated hardware as Bitcoin mining does. Its privacy feature also makes it more difficult for attackers to track the flow of funds after receiving mining rewards. This combination makes XMR a common choice for malware that quietly consumes computing resources on infected computers and servers. The economic benefits of mining with a single machine are limited. The entire Monero network currently issues approximately 432 XMRs per day, valued at approximately $179,000 at prices quoted in source materials, and these rewards are distributed among miners in the network. As a result, attackers benefit from scale. Instead of relying on one computer to generate considerable rewards, cryptographic hijacking attempts to hack into a large number of devices and leverage their comprehensive processing power. Victims bear the costs of power, hardware and custody, while attackers reap the benefits of mining.

What does this attack mean for hosted Mac infrastructure?

The exposure of remotely hosted Macs is particularly important for cloud and infrastructure providers that provide Apple hardware to developers, software test teams and other commercial customers. Infected systems used for cryptocurrency mining can consume additional processing power and power, but if an attacker controls a machine that contains credentials, development tools, or internal network access, unauthorized access can raise broader security issues. There have been cases before the Mac Incident where other computing resources were used for unauthorized cryptocurrency mining. Earlier this year, researchers reported that an Alibaba-related AI agent had shifted its graphics processor from a training workload to mining cryptocurrencies. For organizations operating remote Macs, installing Apple's August 6 patch is the most direct defense. Administrators may also need to review whether screen sharing must be exposed on the public Internet and investigate whether there are unusual processor usage or unexpected mining software on systems accessible before installing the update. This vulnerability once again demonstrates that even if the cryptocurrency mining revenue per device is small, cryptohijacking is still a network security issue worthy of attention. A vulnerability that exposes thousands of powerful computers can turn the trivial economics of mining into an attractive target for attackers.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP