The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials. It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.
https://www.techradar.com/pro/secur...-which-can-turn-macs-into-cryptomining-slaves
I guess this screen-sharing stuff should normally be turned off, and it's blocked by the firewall? But it still seems to be a serious flaw in macOS.
https://www.techradar.com/pro/secur...-which-can-turn-macs-into-cryptomining-slaves
I guess this screen-sharing stuff should normally be turned off, and it's blocked by the firewall? But it still seems to be a serious flaw in macOS.