A vulnerability in the macOS screen sharing feature is being actively exploited by hackers to deploy Monero (XMR) mining software on victims’ machines without their knowledge. The Dutch cybersecurity agency has officially sounded the alarm, with US authorities quickly following suit — assigning the flaw a critical severity score of 9.8 out of 10 on the CVSS scale.
It is a silent, hard-to-detect attack that directly targets the computing power of Apple devices — and a stark reminder of why Monero remains the go-to cryptocurrency for cybercriminals specializing in cryptojacking.
Here is everything you need to know — and, more importantly, what you need to do immediately.
A macOS Flaw Scored 9.8/10: Why This Is Alarming
The CVSS (Common Vulnerability Scoring System) is the internationally recognized benchmark for measuring the severity of security vulnerabilities. A score of 9.8 out of 10 places this flaw firmly in the “critical” category — the highest tier short of a perfect 10. In practical terms, this means the vulnerability can be exploited remotely, with no prior authentication required, and carries the potential for total compromise of the affected system.
The vulnerability targets the Screen Sharing service built into macOS, a feature widely used in remote work and professional environments. Hackers are exploiting this weakness to gain partial control of the machine and silently deploy Monero (XMR) mining software. In most cases, users notice nothing beyond degraded performance and abnormal overheating of their device.
The Dutch cybersecurity agency (NCSC-NL) has confirmed active exploitation cases in the wild. US authorities were quick to follow with their own advisory, underscoring the urgency of the situation for all macOS users — particularly those who have enabled screen sharing in their system preferences.
Monero, the Go-To Crypto for Cryptojacking: Why Hackers Love It
Cybercriminals’ preference for Monero (XMR) is no coincidence. Unlike Bitcoin or Ethereum, Monero is built from the ground up for complete anonymity: sender and recipient addresses, as well as transaction amounts, are cryptographically concealed through technologies including Ring Signatures, Stealth Addresses, and RingCT. Tracing funds generated through illicit XMR mining is therefore extremely difficult, even for law enforcement agencies.
Furthermore, Monero’s mining algorithm — RandomX — is specifically optimized for consumer-grade processors (CPUs), unlike Bitcoin, which requires specialized ASIC hardware. This means any MacBook or iMac can be turned into a profitable miner with no dedicated equipment whatsoever. Hackers bear zero infrastructure costs: they simply parasitize their victims’ computing power and electricity.
This attack model — known as cryptojacking — has been on the rise since 2023. According to cybersecurity data published by firms such as CrowdStrike and SentinelOne, malicious mining campaigns targeting macOS environments have grown significantly, as hackers look to diversify their targets beyond the Linux servers they have traditionally focused on.
What to Do Immediately to Protect Your Mac
Experts are unanimous in their response: update macOS without delay. Apple has released a security patch to address this vulnerability, and installing the latest version of the operating system is your first line of defense. Head to System Settings > General > Software Update to check your current version.
Beyond updating, several additional steps are strongly recommended:
- Disable Screen Sharing if you are not actively using it (System Settings > General > Sharing).
- Monitor CPU activity via Activity Monitor: an unknown process consuming an abnormal share of resources may indicate a miner running in the background.
- Audit outbound network connections using a tool such as Little Snitch to detect any communications with mining pools.
- Enable the macOS firewall and restrict unnecessary inbound access.
This attack reflects a deeper trend: privacy-focused cryptocurrencies like Monero continue to attract malicious actors who exploit every available system vulnerability to quietly monetize their access. For Apple users — long considered less exposed than their Windows counterparts — this is a blunt reminder that no ecosystem is immune to crypto-related cyber threats.