macOS security bug went unreported due to Apple being deluged by AI slop reports
0 Join the conversation Follow us Add us as a preferred source on Google Bynario disclosed CVE‑2026‑43760, a macOS RCE flaw allowing root file creation via legacy VNC password option Apple patched it July 27, 2026 in ma…
0 Join the conversation Follow us Add us as a preferred source on Google Bynario disclosed CVE‑2026‑43760, a macOS RCE flaw allowing root file creation via legacy VNC password option Apple patched it July 27, 2026 in macOS Tahoe 26.6 and Sonoma 14.8.8; unpatched users should disable Screen Sharing/Remote Management or the legacy VNC setting Reporting was delayed as Apple limited submissions due to AI‑generated bug report overload, but the company reached out directly to fix this issue Apple has fixed a high-severity vulnerability that allowed threat actors to execute malicious code remotely (RCE), as root, on certain macOS devices - and would have probably fixed the issue even sooner; had it not been flooded with AI slop vulnerability reports. Security researchers Bynario published an in-depth report discussing finding an RCE flaw on macOS 26.5.2 devices running on Apple Silicon M4 and M5 systems, with System Integrity Protection (SIP) enabled. According to Bynario, the vulnerability affects Mac devices with Screen Sharing or Remote Management enabled, and with the legacy "VNC viewers may control screen with password" option turned on. For those devices, should a threat actor obtain the VNC password and authenticate to the Mac (no macOS account compromise is required, only the VNC password), they would be able to perform file-transfer operations, with root permissions, due to a logic flaw. Latest Videos FromTechRadar Watch full video here: Drowning in the AI flood The attacker would then be able to create new files owned by root anywhere the system allows. In the report, the researchers demonstrated creating a valid file inside /private/etc/sudoers.d, granting passwordless sudo privileges, and once that policy was in place, they were able to run commands as root. In a separate report, the researchers said Apple was forced to limit the number of active bug reports individual researchers can keep open at one time, due to its security teams being flooded with AI slop reports. Since they already hit that threshold by submitting more than 50 bugs in three weeks, the researchers were unable to report this RCE flaw sooner. However, they explained that Apple reached out to Bynario directly to review, and later patch, the flaw. The bug is now tracked as CVE-2026-43760 and was given a severity score of 8.6/10 (high). Apple released the updates on July 27, 2026, addressing the bug on macOS Tahoe 26.6 and macOS Sonoma 14.8.8. Those who cannot patch should disable the legacy "VNC viewers may control screen with password" option or disable Screen Sharing and Remote Management entirely. The best antivirus for all budgets Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. CATEGORIES LATEST ARTICLES 1 Our favorite high-end music player brand just unveiled a successor to its 5-star entry-level DAP — though its definition of 'entry-level' might differ to yours 2 Google now lets you sync Fitbit health data to Apple Health on iOS 3 Best mini PC 2026 deals — save on compact machines from Geekom, GMKtec, and more 4 With great power comes a great quiz — put your Spider-Man fandom to the ultimate test 5 Leaked document suggests Microsoft's rumored 'disc-to-digital' feature will roll out this month and allow users to play the Xbox 360 catalogue on Project Helix