A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports
- Bynario disclosed CVE‑2026‑43760, a macOS RCE flaw allowing root file creation via legacy VNC password option
- Apple patched it July 27, 2026 in macOS Tahoe 26.6 and Sonoma 14.8.8; unpatched users should disable Screen Sharing/Remote Management or the legacy VNC setting
- Reporting was delayed as Apple limited submissions due to AI‑generated bug report overload, but the company reached out directly to fix this issue
Apple has fixed a high-severity vulnerability that allowed threat actors to execute malicious code remotely (RCE), as root, on certain macOS devices - and would have probably fixed the issue even sooner; had it not been flooded with AI slop vulnerability reports.
Security researchers Bynario published an in-depth report discussing finding an RCE flaw on macOS 26.5.2 devices running on Apple Silicon M4 and M5 systems, with System Integrity Protection (SIP) enabled.
According to Bynario, the vulnerability affects Mac devices with Screen Sharing or Remote Management...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE