A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports



  • Bynario disclosed CVE‑2026‑43760, a macOS RCE flaw allowing root file creation via legacy VNC password option
  • Apple patched it July 27, 2026 in macOS Tahoe 26.6 and Sonoma 14.8.8; unpatched users should disable Screen Sharing/Remote Management or the legacy VNC setting
  • Reporting was delayed as Apple limited submissions due to AI‑generated bug report overload, but the company reached out directly to fix this issue

Apple has fixed a high-severity vulnerability that allowed threat actors to execute malicious code remotely (RCE), as root, on certain macOS devices – and would have probably fixed the issue even sooner; had it not been flooded with AI slop vulnerability reports.

Security researchers Bynario published an in-depth report discussing finding an RCE flaw on macOS 26.5.2 devices running on Apple Silicon M4 and M5 systems, with System Integrity Protection (SIP) enabled.

https://cdn.mos.cms.futurecdn.net/gth8FZBY7MR8cmk3vbbJ6N-1920-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img