A critical security vulnerability in Apple's Screen Sharing feature has shifted from theoretical threat to active exploitation, with hackers already targeting Mac users across the internet. Dutch cybersecurity officials have documented multiple cases where attackers successfully breached Mac computers through the flaw, achieving root-level access — the highest form of control possible over a device — before installing cryptocurrency-mining software designed to exploit the infected machine's processing power at the owner's expense. The development underscores the widening gap between the time technology companies patch vulnerabilities and when criminals weaponise those same flaws at scale.

The Dutch National Cyber Security Centre's disclosure carries particular weight because it represents the first public confirmation that the vulnerability, tracked as CVE-2026-65400, has moved beyond controlled security research environments into the hands of active threat actors. When Apple initially released its emergency patch this month, the company stated it had no knowledge of the flaw being exploited in the wild. That reassurance has evaporated within weeks, transforming what appeared to be a manageable security incident into a pressing concern for the estimated hundreds of millions of Mac users worldwide.

Monero, the cryptocurrency of choice in these attacks, occupies a unique position in the criminal economy. Unlike Bitcoin, which requires specialised hardware to mine profitably, Monero remains viable for mining on standard computer processors. This characteristic makes it ideal for exactly this scenario: attackers can quietly harness the computational resources of thousands of compromised machines without requiring expensive or easily traceable equipment. The attackers essentially convert each infected Mac into a money-printing machine, with the true owner bearing the electricity costs and hardware degradation while criminals pocket the mining proceeds.

Tom Hegel, a threat researcher at SentinelOne's research division SentinelLABS, emphasises that the cryptocurrency-mining angle, while visible and quantifiable, likely represents only part of the threat picture. Once attackers achieve root access through this vulnerability, they gain capabilities far exceeding simple resource exploitation. The compromised system becomes a potential springboard for accessing sensitive files, harvesting stored passwords and authentication credentials, stealing cloud account tokens, and potentially pivoting to connected corporate networks. The Monero miner may be the most conspicuous malicious payload, but it may mask more sophisticated activities running simultaneously on the infected device.

The Screen Sharing feature itself is a legitimate Apple tool designed for remote support and accessibility. It permits one computer to view and control another Mac across a network, a functionality that many users and organisations depend on for technical assistance and collaborative work. The vulnerability resides in how this feature validates incoming requests, allowing attackers to access the capability without proper authentication. What transforms this into a particularly dangerous scenario is the nature of many organisations' network configurations: companies and institutions frequently expose their infrastructure to the internet to enable remote work and support, inadvertently creating open pathways to vulnerable systems.

Apple distributed patches across three major macOS versions to address this issue: Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. The release of fixes across multiple versions simultaneously itself signals Apple's assessment of the threat's severity. Updating requires navigating to System Settings, selecting General, then Software Update — a process most users can complete in minutes. For those who have never used Screen Sharing and have no intention of doing so, disabling the feature entirely through System Settings provides an additional layer of protection while awaiting updates. Yet the simplicity of the fix stands in sharp contrast to the difficulty in ensuring all vulnerable systems receive the patch in time.

The real-world exploitation observed in the Netherlands involved Macs whose Screen Sharing ports were exposed to the public internet. Most standard home routers and corporate firewalls block such exposure by default, meaning the typical consumer's Mac sitting at home behind a residential router faces relatively lower risk. However, businesses operating servers, remote-access infrastructure, or allowing employees to enable Screen Sharing for support purposes may have significantly more exposure. Any organisation that confirmed Screen Sharing accessibility before the patch was deployed faces an additional imperative: patching the vulnerability only closes the door, it does nothing to remove any malware already installed or reverse any actions attackers may have taken.

Federal cybersecurity assessments have assigned this vulnerability a CVSS score of 9.8 out of 10, placing it in the critical category where exploitation requires neither valid user credentials nor any interaction from the targeted user. The attacker simply needs to reach the vulnerable service. This score reflects the combination of ease of exploitation, the severity of consequences, and the breadth of potentially vulnerable systems. SentinelOne researcher Phil Stokes previously noted that Apple's decision to issue an out-of-cycle security patch — departing from the company's standard monthly update schedule — already signalled the urgency with which Apple's own engineers viewed the threat.

For Malaysian and Southeast Asian businesses and individuals, the implications warrant immediate attention. The region's rapid digital transformation has expanded reliance on remote access tools, cloud services, and cross-border technical support, all of which increase exposure to vulnerabilities like this one. Moreover, the prevalence of older, unpatched systems in some organisations — whether through budget constraints, legacy application compatibility, or simple administrative oversight — means that portions of the regional computing infrastructure remain vulnerable. The cryptocurrency-mining angle may prove particularly concerning in countries where electricity costs are subsidised or underpriced relative to global averages, making such attacks disproportionately lucrative for criminals.

The broader lesson extends beyond this single vulnerability. Attackers operate on a timeline that often surprises security professionals: the interval between a patch's release and widespread exploitation can compress to mere weeks rather than the months cybersecurity professionals once expected. Every unpatched system becomes an opportunity for criminals to gain foothold, extract data, or commandeer resources. Apple users who have deferred updating their systems now face an explicit demonstration of why security patches demand attention. Those who have already updated can serve as models for their professional and personal networks, while those responsible for managing Mac deployments in organisations should use this incident as justification for implementing mandatory patch-management policies that treat critical vulnerabilities as true emergencies rather than routine maintenance.