← Back

security

Hackers Exploit macOS Screen Sharing Flaw to Mine Monero

Cyber attackers have exploited a flaw in macOS Screen Sharing to gain root access and install Monero miners. Public proof-of-concept code has now emerged, highlighting the severity of the vulnerability.

AS1 NewsSource: decrypt.co

securitymacosvulnerabilitycryptominingmonerocybersecurity
XMR$515.27-4.00%

The Dutch cyber agency has reported that malicious actors have taken advantage of an authentication flaw in macOS Screen Sharing. This vulnerability allows attackers to gain root access to affected systems, enabling them to install Monero mining software covertly. The attack method involves exploiting the flaw to bypass security measures, then deploying mining malware without user consent.

Security researchers have observed that the attackers are using publicly available proof-of-concept code to demonstrate the exploit, which could facilitate wider malicious activity if adopted by other threat actors. The circulating code underscores the importance of timely security updates and patches from Apple to mitigate the risk.

This vulnerability raises concerns about the security of remote access features in macOS, especially given the popularity of Screen Sharing for remote support and collaboration. Users are advised to ensure their systems are updated with the latest security patches and to disable Screen Sharing if not in active use.

While Apple has not yet issued an official statement regarding this specific flaw, the circulating proof-of-concept emphasizes the need for vigilance among macOS users and administrators. The incident also highlights the ongoing risks associated with remote access tools and the importance of robust security practices in protecting against covert cryptocurrency mining activities.

negative

The exploit allows unauthorized root access, enabling covert Monero mining, which can compromise system integrity and security.