- Apple Support recently disclosed that it patched a key vulnerability in versions of macOS supporting the Screen Sharing feature.
- Dutch authorities warned that attackers exploited the flaw to deploy a Monero (XMR) mining network on Apple devices with internet access.
The Screen Sharing Vulnerability on macOS
Apple, the world’s second-largest company by market cap, confirmed it found a major macOS vulnerability. It enables hackers to bypass its Screen Sharing application without valid credentials. The company detected the issue in the operating system’s Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1 versions.
According to Apple, it has already patched the problem. Hence, it advised customers to update their devices to the latest firmware versions. Doing so would prevent unauthorized access to systems connected to a local network or exposed directly on the internet.
Apple said it solved the problem by enhancing the systems’ state management mechanisms to enforce appropriate login credential validation and block unauthorized authentication attempts.
Hackers Installing Monero Miners on Apple Devices
Along the way, a notice from the Netherlands’ National Cyber Security Center (NCSC) has revealed an alarming hacking activity related to Apple’s Screen Sharing vulnerability. It informed the public that hackers remotely installed Monero crypto miners on unsuspecting users’ devices using the exploit.
Citing a report it received from an unnamed source, the NCSC claimed that perpetrators accessed “multiple systems” using the vulnerability. It didn’t provide the numbers, but it involved systems with their port 5900, a default network port for Virtual Network Computing (VNC), accessible from the internet.
The USA’s National Vulnerability Database (NVD) rated the vulnerability 9.8 out of 10, indicating the critical risk the problem poses to affected users.
Monero Cryptojacking Incidents
IBM, one of the world’s largest technology companies, defines cryptojacking as a type of cyberattack in which malicious actors gain unauthorized access to a device to use it for crypto mining. It uses the victim’s own compute resources to the detriment or without the benefit of a reward to the affected user.
Several cybersecurity firms, such as Trellix, claim that Monero’s XMR coin is among the most preferred assets of cryptojackers. This is owing to the chain’s privacy-centric design that can obfuscate transactions. However, there are currently no specific figures related to the matter.
Still, SentinelOne, an AI-powered cybersecurity firm, estimates that over $6.5 million worth of cryptojacking incidents were recorded in early 2026. Assuming a Compound Annual Growth Rate (CAGR) of 10.9%, it could grow by $3.18 billion in 2030 if the trend is left unchecked.







