Attackers have exploited an authentication flaw in macOS Screen Sharing to gain root access and plant Monero miners on affected systems. The Dutch cyber agency reported the exploitation, and public proof-of-concept code is now circulating.
How the attack works
The vulnerability sits in Screen Sharing, the built-in macOS feature that lets a user remotely control another Mac. By bypassing authentication, an attacker can escalate to root privileges — the highest level of system control. That gives them full reign to install software, modify settings, or disable security tools without the owner's knowledge.
In this case, the attackers used that access to install Monero miners. These programs quietly consume CPU and GPU power to mine cryptocurrency. Monero is a favored coin for such schemes because its blockchain hides transaction details, making payments nearly impossible to trace. The mining itself can cause noticeable side effects: louder fans, higher electricity bills, and sluggish performance.
What the Dutch agency reported
The Dutch cyber agency confirmed the exploit is being used in the wild, but its report offers few specifics. It didn't name the victims, the attackers, or the number of machines affected. It also didn't say which macOS versions are vulnerable or whether Apple has been notified of a patch timeline.
The agency's warning makes clear this isn't a hypothetical flaw. It's already been weaponized. For Mac users, that's a reminder that Screen Sharing, often left enabled for remote work or IT support, can become a doorway for attackers if left unpatched.
Proof-of-concept code goes public
Proof-of-concept code for the flaw is now publicly available. That's a significant development. Before, only the original attackers had a working exploit. Now anyone with basic technical skills can adapt the code to target vulnerable Macs.
Public POC code tends to accelerate exploitation. Even attackers without deep knowledge of macOS internals can use it to gain root access and install their own payloads. The Monero mining operation that triggered the Dutch agency's report might just be the first of many.
The agency's report did not identify the attackers or how many systems were hit. With the proof-of-concept code now out, the threat is no longer confined to the original campaign. Mac users who rely on Screen Sharing should treat this as an urgent warning.


