Exploited in the wild macOS Screen Sharing auth-bypass Apple malware
Хакеры используют уязвимость в macOS Screen Sharing для установки майнеров
CVE Tools coverage
The Netherlands' NCSC reported active exploitation of CVE-2026-65400, a critical authentication bypass in macOS Screen Sharing that grants attackers root access without valid credentials. This vulnerability allows intruders to install Monero cryptocurrency miners on affected systems, as evidenced by recent incident reports. Apple resolved the issue on August 6, 2026, by releasing patches for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.