Community Trust ScoreVerified
Dutch cybersecurity officials found it. A critical flaw buried inside macOS Screen Sharing — scored 9.8 out of 10 on the CVSS scale — is being actively exploited by hackers to quietly install Monero mining software on victims’ computers, and most users probably have no idea it’s happening.
The Dutch cyber agency’s alert landed hard. Screen Sharing is a built-in macOS feature that lets remote users take control of a machine — legitimate, useful, and now a serious liability. Hackers figured out they can abuse the flaw to push Monero mining software onto affected systems without the owner ever clicking anything suspicious or noticing a login prompt. No physical access needed. No warning. The machine just starts working for someone else. Monero is the coin of choice here for a pretty clear reason: it’s built for privacy, with transactions that are basically untraceable, which makes it far harder for investigators to follow the money trail back to whoever’s running the operation.
Not a minor bug. A 9.8.
Why Monero and Why Now
Monero has been the go-to coin for illicit mining for years. It’s not the biggest cryptocurrency by market cap, but its privacy architecture — ring signatures, stealth addresses, confidential transactions — makes it uniquely attractive for attackers who want to monetize stolen computing power without leaving obvious fingerprints. Other cryptocurrencies are far easier to trace on public blockchains. With Monero, the flow of funds goes murky fast.
Cryptojacking, which is the practice of hijacking someone else’s hardware to mine crypto, has grown into a serious and persistent threat across the industry. Attackers don’t need to steal passwords or drain bank accounts. They just need access to processing power, and they can quietly earn while the victim pays the electricity bill. The macOS Screen Sharing flaw hands them exactly that — remote access, no noise, no obvious breach.
U.S. officials assigned the 9.8 CVSS rating, which puts it near the absolute top of the severity scale. For context, a perfect 10 is essentially a worst-case scenario. A 9.8 isn’t far off. The rating factors in how easy the flaw is to exploit remotely, whether authentication is required (it’s not, apparently), and the potential impact on affected systems. On all those counts, this one scores badly.
What Users Are Seeing — and Missing
That’s the sneaky part. Most victims won’t see a dramatic warning or a ransomware splash screen. What they’ll see — maybe — is a machine running slower than usual. The fan spinning up for no obvious reason. A laptop getting warm when it’s just sitting there. Unexpected spikes in electricity usage over time. Those are the signs, and they’re easy to dismiss as a software glitch or a browser tab gone rogue.
Security experts are urging macOS users to update their systems immediately. The patches exist. Apple has pushed fixes, and the Dutch agency is telling users to verify they’re running the latest version. That’s the short answer: update now, don’t wait.
But there’s more to it. Strong passwords help. Two-factor authentication adds another layer. Monitoring system performance for unexplained slowdowns or overheating is worth doing, especially for anyone who uses Screen Sharing regularly for remote work. The Dutch agency is also asking users to report unusual activity — that data feeds into a broader effort to map how widely the flaw has been exploited and who’s behind it.
The full technical details of the exploit haven’t been made public, probably to avoid handing attackers a cleaner roadmap. That’s standard practice when a patch is already available but adoption is still rolling out. No specific timeline for a complete resolution has been given. The investigation is ongoing.
International Response and Lingering Questions
The Dutch agency isn’t working alone. International cybersecurity experts are in the loop, and the collaboration is focused on tracking the exploit’s spread and building better defenses. It’s unclear yet how many machines have been compromised, or how long the campaign has been running before the agency caught it. Those details may come later — or they may not, if investigators decide disclosure risks tipping off the attackers.
What’s clear is the scope of potential exposure. macOS has a large and often security-conscious user base, but “security-conscious” doesn’t mean immune, especially when a flaw sits in a trusted system feature most users assume is safe. Screen Sharing isn’t some obscure utility. It’s baked into macOS and used by millions of people, from remote workers to IT teams to families helping relatives troubleshoot from across the country.
And attackers know that. They’re not going after obscure attack surfaces. They’re going after the stuff everyone uses and nobody thinks to question.
The Dutch agency’s investigation continues, with the focus on preventing further unauthorized installations and understanding the full scale of the Monero mining campaign tied to this flaw.
Frequently Asked Questions
What macOS feature is being exploited in this attack?
Hackers are exploiting a vulnerability in the macOS Screen Sharing feature, which allows remote users to control a computer, to install Monero mining software without the owner’s knowledge.
How serious is the macOS Screen Sharing vulnerability?
U.S. officials rated it 9.8 out of 10 on the CVSS scale, making it a critical-severity flaw — one of the highest possible ratings for a security vulnerability.
Why do attackers use Monero instead of Bitcoin for cryptojacking?
Monero’s privacy features make its transactions untraceable, which makes it far harder for investigators to follow the money back to the attackers running the mining operation.
Why It Matters
The discovery of this critical vulnerability in macOS Screen Sharing underscores the increasing risks associated with remote access tools, especially as they become targets for cybercriminals. As Monero mining operations can be conducted discreetly, this incident highlights the broader implications for users' security and system performance, potentially leading to increased scrutiny on software vulnerabilities that facilitate illicit activities. Moreover, this situation may prompt a reevaluation of cybersecurity protocols among both individual users and organizations, especially in environments where remote access is prevalent.
