Critical macOS Screen Sharing Authentication Flaw (CVE‑2026‑65400) Enables Remote Crypto Mining
What It Is — A critical authentication bypass in Apple macOS’s Screen Sharing service (CVE‑2026‑65400) lets an attacker who can reach the service over the network obtain remote code execution and silently install a Monero cryptocurrency miner. Apple released a patch, but the NCSC‑NL confirms the vulnerability is being actively exploited in the wild.
Exploitability — Public exploit code is circulating; active exploitation observed. CVSS 9.8 (Critical).
Affected Products — Apple macOS 12.7 and later (all versions that include the vulnerable Screen Sharing component).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Logical Access) mandates documented, enforceable controls over remote access mechanisms; an unpatched screen‑sharing flaw constitutes a direct control failure.
- Continuous monitoring of privileged sessions is required evidence for audit; exploitation demonstrates the need for real‑time session logging and alerting.
- Enterprise buyers now expect demonstrable patch‑management cadence and secure configuration as part of the Trust Services Criteria.
Recommended Actions
- Apply Apple’s latest security update to every macOS endpoint without delay.
- Disable or strictly restrict Screen Sharing on any device reachable from the internet; enforce network segmentation for remote‑desktop services.
- Enforce MFA for all remote‑access pathways and ensure all screen‑sharing sessions are logged to a SIEM or equivalent monitoring platform.
- Automate inventory and compliance checks to verify patch status and capture evidence for SOC 2 audits.
- Update SOC 2 access‑control policies to include periodic reviews of remote‑desktop configurations and associated risk assessments.
Source: The Hacker News