macOS Screen Sharing Auth Bypass Exploited in Wild
Netherlands NCSC confirms active exploitation of a macOS Screen Sharing authentication bypass after public PoC release. Attackers deploying Monero cryptocurrency miners.

Exploitation confirmed.
The Netherlands’ National Cyber Security Centre (NCSC) is warning organizations that attackers are actively exploiting an authentication bypass in macOS Screen Sharing. The campaign accelerated after public proof-of-concept exploit code emerged. Source: BleepingComputer, August 14, 2026.
Payload confirmed. Observed post-exploitation activity: deployment of a Monero cryptocurrency miner. Cryptojacking, not ransomware — but unauthorized remote access on a compromised host means full execution capability, regardless of what the current operators chose to run.
CVE status. A specific CVE identifier has not been confirmed in available open sources as of publication time. Unconfirmed — treat accordingly.
Patch status. No official Apple patch has been announced as of this writing. Assume any macOS host with Screen Sharing enabled and reachable is exposed.
What to do now
If Screen Sharing is not operationally required: disable it.
→ System Settings → Sharing → Screen Sharing → toggle off
This eliminates the exposed attack surface regardless of patch timeline.
If Screen Sharing must remain active: restrict inbound access at the network layer. macOS Screen Sharing (VNC) runs on TCP port 5900. Firewall rules scoping that port to known management hosts only are an effective interim control. Host-based and network-perimeter rules both apply.
Detection posture: monitor for sustained high CPU from unexpected processes, new outbound connections to cryptocurrency mining pools, and processes spawned under a remote-access account context. Endpoint detection that flags cryptominer behavior should catch the observed payload class even without a signature for the initial access vector.
No CVE, no patch, active public PoC in circulation. Watch for an Apple security advisory and a potential CISA KEV addition.
Related: Apple is separately rolling out on-device Threat Notifications for mercenary spyware targets — a different threat vector on the same platform. For macOS malware context, see PAMStealer and the Mac threat ecosystem. More Apple platform vulnerabilities and malware coverage in the Apple topic hub.
Found this useful? Share it.


