A root-access flaw in macOS Screen Sharing let intruders hijack rented Mac machines to run cryptojacking malware
Apple has issued a patch for a macOS security flaw that let attackers seize root-level control of affected machines. The vulnerability was tied to the operating system’s Screen Sharing login process, according to reports on the issue.
Once inside, attackers reportedly used the access to deploy cryptocurrency mining software targeting Monero, a privacy-focused digital asset. Monero has long been a preferred target for so-called cryptojacking campaigns because its mining algorithm can run on standard computer hardware rather than specialized equipment.
A particular concern raised in coverage of the flaw involves rented Mac machines. These are Apple computers offered through cloud or hosting providers so customers can build and test software in a genuine macOS environment. Because such machines are remotely accessible by design, a flaw in a remote-access feature like Screen Sharing carries added risk for hosting providers and their clients.
Root access is the highest level of control on a Unix-based system such as macOS. An attacker who obtains it can install software, alter system files, and monitor activity largely undetected. In this case, that access was reportedly used to run Monero mining code in the background, consuming a machine’s processing power without the operator’s knowledge.
Cryptojacking has been a persistent problem across both personal and cloud computing environments for several years. Attackers favor the tactic because it can generate steady returns while avoiding the more direct legal exposure of theft or ransomware. Detection can also be difficult, since mining software often runs quietly and mimics legitimate background processes.
Apple’s patch addresses the underlying authentication weakness in Screen Sharing that allowed the root-level bypass. Users and organizations running affected macOS versions are typically advised to apply security updates promptly once a fix becomes available, particularly for systems that are remotely accessible or rented out for shared use.
The incident underscores a broader pattern in which operating system vulnerabilities are increasingly monetized through covert cryptocurrency mining rather than more visible forms of attack. It also highlights the specific exposure faced by providers that rent out Mac hardware, since those machines are often left accessible for extended periods to support remote development work.
The direct financial impact on Monero’s market is likely to be limited, since cryptojacking incidents typically generate mining rewards without materially moving trading volume or price. Monero has repeatedly been linked to unauthorized mining schemes because of its accessible mining process, and this episode fits that established pattern rather than introducing a new market dynamic.
The larger significance lies in enterprise and cloud security rather than crypto markets themselves. Providers renting Mac infrastructure may face renewed scrutiny over how remote-access features are configured and patched. Continued reports of hidden mining activity could also add to broader concerns about the security posture of machines used in cloud and rental computing environments.
Apple’s patch closes a specific authentication gap in Screen Sharing, but the episode is another reminder that operating system flaws can be quietly turned into cryptocurrency mining operations well before they are detected.
It was a flaw in the Screen Sharing login process that allowed attackers to gain root-level access to affected Mac machines.
Attackers reportedly used the root access gained through the flaw to install cryptocurrency mining software that generated Monero without the machine operator’s knowledge.
Rented Macs are made remotely accessible by hosting providers so customers can use macOS in the cloud, and the Screen Sharing flaw could be exploited through that same remote-access pathway.
Monero can be mined using standard computer processors rather than specialized hardware, making it a common choice for attackers who hijack compromised machines.
Users and organizations are generally advised to install the latest macOS security updates promptly, especially on machines that are remotely accessible or shared among multiple users.
Original source: AltcoinGordon
Syndicated coverage. Originally reported by altcoingordon.com.