A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports
Security researchers found a high-severity RCE flaw, which Apple later fixed.
Apple discovered a critical vulnerability in macOS, allowing threat actors to execute code remotely with root privileges. This flaw, known as CVE-2026-43760, affects macOS devices running version 26.5.2 or later on Apple Silicon M4 and M5 systems, particularly when Screen Sharing or Remote Management is enabled, and the legacy VNC viewer with a password option is active. The vulnerability enables attackers to create files with root permissions, thereby gaining full control over the system.
Bynario, a security researcher, reported the issue but faced delays in the reporting process due to Apple's overwhelmed bug reporting system. This was caused by an influx of AI-generated vulnerability reports. Apple, however, proactively reached out to Bynario to address the vulnerability. The company released patches for the flaw on July 27, 2026, in macOS Tahoe 26.6 and Sonoma 14.8.8.
For users unable to apply the patch, Apple advises disabling Screen Sharing and Remote Management, or turning off the legacy VNC viewer with the password option. These steps can prevent attackers from exploiting the vulnerability. The severity of the flaw is rated high, with a score of 8.6 out of 10.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Apple and the invisible wolf: AI slop drowns real security threats computerworld.com