macOS Screen Sharing Authentication Flaw (CVE‑2026‑65400) Enables Remote Root Access and Monero Mining
What It Is — A pre‑authentication vulnerability in macOS’s built‑in Screen Sharing service allows an attacker on the network to authenticate without valid credentials, gaining full root privileges. Apple released patches in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.
Exploitability — Actively exploited in the wild within two weeks of disclosure; attackers scan for systems with TCP 5900 exposed and install Monero miners. CVSS 9.8 (Critical).
Affected Products — Apple macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9 (any version prior to these patches).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Controls – The flaw bypasses authentication, directly violating the Logical Access (CC6.1) and System Operations (CC7.1) criteria that require verified identity before privileged actions.
- Continuous Monitoring – Detecting unauthorized remote sessions and unexpected cryptomining processes is essential evidence for the Monitoring (CC8.1) control set.
- Audit Trail Integrity – Unpatched endpoints can create gaps in log completeness, jeopardizing the System Monitoring and Change Management controls auditors scrutinize during SOC 2 examinations.
Recommended Actions
- Deploy Apple’s security updates (macOS Tahoe 26.6.1, Sequoia 15.7.9, Sonoma 14.8.9) across all managed Macs.
- Disable Screen Sharing on devices that do not require remote desktop, or restrict it to trusted internal subnets via firewall rules.
- Enforce MFA for any remote access solution and ensure session logging is enabled and retained per SOC 2 requirements.
- Implement continuous endpoint monitoring to flag unexpected processes (e.g., cryptominers) and anomalous remote logins.
- Document remediation steps and retain patch‑deployment evidence for audit readiness.
Source: Security Affairs – macOS Screen Sharing Flaw Exploited to Deploy Monero Miners