Skip to main content

Apple macOS Screen Sharing Logic Flaw Actively Exploited to Deploy Monero Miner via Root Command Execution (CVE-2026-43760)

Scope: macOS Systems with Screen Sharing or Remote Management Enabled and VNC Password Authentication Turned On (macOS Tahoe Prior to 26.6 and macOS Sonoma Prior to 14.8.8)

Severity: High

BleepingComputer confirmed today, August 17, 2026, that hackers are actively exploiting CVE-2026-43760, a logic flaw in macOS Screen Sharing's VNC authentication path discovered by Bynar researchers, to deploy Monero cryptocurrency miners on unpatched Mac systems. The vulnerability exists because macOS Screen Sharing's file copy helpers (SSFileCopySender and SSFileCopyReceiver) run as root when a user connects via VNC password authentication rather than native Apple authentication, allowing a remote attacker to read any protected file and write arbitrary files with root authority, including creating a valid sudoers policy that grants passwordless root access via a single subsequent command. Apple patched the flaw on July 27, 2026, but the gap between patch availability and widespread update adoption has allowed active exploitation to begin. Organizations and individuals running macOS with Screen Sharing or Remote Management enabled must update to macOS Tahoe 26.6 or macOS Sonoma 14.8.8 immediately, and where updating is not possible, disable the "VNC viewers may control screen with password" option immediately as it fully removes the attack surface.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.