This macOS Screen Sharing Flaw Is Silently Mining Crypto

·
Listen to this article~5 min

A critical macOS Screen Sharing flaw is being actively exploited to install Monero miners. Learn how to protect your Mac before it's too late.

You probably don't think twice about the Screen Sharing app on your Mac. It's one of those built-in tools that just works, letting you hop into another machine on your network or remotely access your desktop from the couch. But here's the thing: that quiet little utility just became a major security headache. The Netherlands' National Cyber Security Centre (NCSC) is sounding the alarm about an actively exploited authentication bypass vulnerability in macOS. The worst part? Public exploit code is already out there, which means this isn't just a theoretical threat. Hackers are using it right now to sneak Monero miners onto vulnerable systems. ### What's Actually Happening Let's break this down without the jargon. The flaw lives in macOS Screen Sharing, and it lets an attacker bypass the authentication process entirely. In plain English: if your Mac has Screen Sharing enabled, someone on your network (or remotely, if you've exposed the service) can get in without a password. Once they're in, they don't steal your files or hold your data for ransom. Instead, they're doing something sneakier. They're installing a cryptocurrency miner that quietly uses your Mac's processing power to mine Monero, a privacy-focused digital currency. Your Mac slows down, the fans spin up, and your electricity bill creeps higher. All while you have no idea anything's wrong. The NCSC's warning follows the emergence of public exploit code, which dramatically lowers the barrier for entry. It's no longer just elite hackers with custom tools; now anyone with basic technical skills can pull this off. ### Why Monero Miners Are the Go-To for Hackers You might wonder why hackers bother with crypto mining instead of ransomware or data theft. The answer is simple: it's quieter and often more profitable over time. Monero is specifically designed to be mined on regular CPUs, which makes it perfect for this kind of attack. Ransomware screams for attention. It locks your files, displays a scary message, and demands payment. That triggers alarms, incident response teams, and law enforcement. Mining, on the other hand, is a slow burn. It doesn't interfere with your work, so you might not notice it for weeks or months. In that time, the attacker can rack up a decent chunk of change while your Mac silently does the heavy lifting. ### How to Protect Your Mac Right Now Here's the good news: there are practical steps you can take today to shut this down. Here's what I'd recommend: - **Disable Screen Sharing if you don't use it.** Go to System Settings > General > Sharing and turn it off. If you're not actively using it, there's no reason to leave the door open. - **Update macOS immediately.** Apple typically patches these vulnerabilities quickly, but only if you install the update. Check for updates and don't put it off. - **Check your running processes.** Open Activity Monitor and look for anything unusual that's eating up CPU. A process named something innocuous but running at 100% could be a miner. - **Use a firewall.** Enable the built-in macOS firewall to block incoming connections that you didn't initiate. - **Change your passwords.** If you've ever used Screen Sharing, change your password and consider using a strong, unique one for your user account. ### The Bigger Picture for Remote Work This vulnerability is a stark reminder that convenience often comes with a cost. Screen Sharing is a fantastic tool for remote work, and plenty of people rely on it daily. But every feature that opens a connection to your machine is a potential entry point for attackers. If you're working from home or managing a small business, it's worth reviewing all your remote access tools. Are you using any other services that expose your Mac to the internet? Things like SSH, VNC, or even cloud-based remote desktop tools all have their own risks. The takeaway here isn't to panic. It's to be intentional. Security isn't about being paranoid; it's about being smart. Take a few minutes to lock down your system, and you'll save yourself a lot of headaches down the road. This particular attack is a perfect example of why staying updated and minimizing your attack surface matters. The hackers aren't targeting you personally, but they're scanning the internet for vulnerable machines. Don't make yours an easy target.