A vulnerability in the macOS screen sharing feature is being actively exploited by hackers to deploy Monero (XMR) mining software on victims’ machines without their knowledge. The Dutch cybersecurity agency has officially sounded the alarm, with US authorities quickly following suit — assigning the flaw a critical severity score of 9.8 out of 10 on the CVSS scale.

It is a silent, hard-to-detect attack that directly targets the computing power of Apple devices — and a stark reminder of why Monero remains the go-to cryptocurrency for cybercriminals specializing in cryptojacking.

Here is everything you need to know — and, more importantly, what you need to do immediately.

A macOS Flaw Scored 9.8/10: Why This Is Alarming

The CVSS (Common Vulnerability Scoring System) is the internationally recognized benchmark for measuring the severity of security vulnerabilities. A score of 9.8 out of 10 places this flaw firmly in the “critical” category — the highest tier short of a perfect 10. In practical terms, this means the vulnerability can be exploited remotely, with no prior authentication required, and carries the potential for total compromise of the affected system.

The vulnerability targets the Screen Sharing service built into macOS, a feature widely used in remote work and professional environments. Hackers are exploiting this weakness to gain partial control of the machine and silently deploy Monero (XMR) mining software. In most cases, users notice nothing beyond degraded performance and abnormal overheating of their device.

The Dutch cybersecurity agency (NCSC-NL) has confirmed active exploitation cases in the wild. US authorities were quick to follow with their own advisory, underscoring the urgency of the situation for all macOS users — particularly those who have enabled screen sharing in their system preferences.

Monero, the Go-To Crypto for Cryptojacking: Why Hackers Love It

Cybercriminals’ preference for Monero (XMR) is no coincidence. Unlike Bitcoin or Ethereum, Monero is built from the ground up for complete anonymity: sender and recipient addresses, as well as transaction amounts, are cryptographically concealed through technologies including Ring Signatures, Stealth Addresses, and RingCT. Tracing funds generated through illicit XMR mining is therefore extremely difficult, even for law enforcement agencies.

Furthermore, Monero’s mining algorithm — RandomX — is specifically optimized for consumer-grade processors (CPUs), unlike Bitcoin, which requires specialized ASIC hardware. This means any MacBook or iMac can be turned into a profitable miner with no dedicated equipment whatsoever. Hackers bear zero infrastructure costs: they simply parasitize their victims’ computing power and electricity.

This attack model — known as cryptojacking — has been on the rise since 2023. According to cybersecurity data published by firms such as CrowdStrike and SentinelOne, malicious mining campaigns targeting macOS environments have grown significantly, as hackers look to diversify their targets beyond the Linux servers they have traditionally focused on.

What to Do Immediately to Protect Your Mac

Experts are unanimous in their response: update macOS without delay. Apple has released a security patch to address this vulnerability, and installing the latest version of the operating system is your first line of defense. Head to System Settings > General > Software Update to check your current version.

Beyond updating, several additional steps are strongly recommended:

  • Disable Screen Sharing if you are not actively using it (System Settings > General > Sharing).
  • Monitor CPU activity via Activity Monitor: an unknown process consuming an abnormal share of resources may indicate a miner running in the background.
  • Audit outbound network connections using a tool such as Little Snitch to detect any communications with mining pools.
  • Enable the macOS firewall and restrict unnecessary inbound access.

This attack reflects a deeper trend: privacy-focused cryptocurrencies like Monero continue to attract malicious actors who exploit every available system vulnerability to quietly monetize their access. For Apple users — long considered less exposed than their Windows counterparts — this is a blunt reminder that no ecosystem is immune to crypto-related cyber threats.

Risk Warning : Trading financial instruments and/or cryptocurrencies carries a high level of risk, including the possibility of losing all or part of your investment. It may not be suitable for all investors. Cryptocurrency prices are highly volatile and can be influenced by external factors such as financial, regulatory, or political events. Margin trading increases financial risks.

CFDs (Contracts for Difference) are complex instruments with a high risk of rapid capital loss due to leverage. Between 74% and 89% of retail investor accounts lose money when trading CFDs. You should assess whether you understand how CFDs work and whether you can afford to take the high risk of losing your money.

Before engaging in financial or cryptocurrency trading, you must be fully informed about the associated risks and fees, carefully evaluate your investment objectives, level of experience, and risk tolerance, and seek professional advice if needed. InvestX.fr and the InvestX application may provide general market commentary, which does not constitute investment advice and should not be interpreted as such. Please consult an independent financial advisor for any investment-related questions. InvestX.fr disclaims any liability for errors, misinvestments, inaccuracies, or omissions and does not guarantee the accuracy or completeness of the information, texts, graphics, links, or other materials provided.

Some of the partners featured on this site may not be regulated in your country. It is your responsibility to verify the compliance of these services with local regulations before using them.

Get 6200 USDT with Bitget ! 🔥

Don't miss out on this offer !
Create your account now to unlock this exclusive reward
Open a Bitget account
close-link
Click Me