A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports
Bynario disclosed CVE‑2026‑43760, a macOS RCE flaw allowing root file creation via legacy VNC password option Apple patched it July 27, 2026 in macOS Tahoe 26.6 and Sonoma 14.8.8; unpatched users should disable Screen Sharing/Remote Management or the legacy VNC setting Reporting was delayed as Apple
<![CDATA[ <article> <ul><li><strong>Bynario disclosed CVE‑2026‑43760, a macOS RCE flaw allowing root file creation via legacy VNC password option</strong></li><li><strong>Apple patched it July 27, 2026 in macOS Tahoe 26.6 and Sonoma 14.8.8; unpatched users should disable Screen Sharing/Remote Management or the legacy VNC setting</strong></li><li><strong>Reporting was delayed as Apple limited submissions due to AI‑generated bug report overload, but the company reached out directly to fix this issue</strong></li></ul><p>Apple has fixed a high-severity vulnerability that allowed threat actors to execute malicious code remotely (RCE), as root, on certain macOS devices - and would have probably fixed the issue even sooner; had it not been flooded with AI slop vulnerability reports.</p><p>Security researchers Bynario <a href="https://bynar.io/blog/a-root-remote-command-execution-on-macos-with-m5-in-2026" target="_blank" rel="nofollow">published</a> an in-depth report discussing finding an RCE flaw on <a href="https://www.techradar.com/best/best-business-mac" target="_blank">macOS</a> 26.5.2 devices running on Apple Silicon M4 and M5 systems, with System Integrity Protection (SIP) enabled.</p><p>According to Bynario, the vulnerability affects Mac devices with Screen Sharing or Remote Management enabled, and with the legacy "VNC viewers may control screen with password" option turned on. For those devices, should a threat actor obtain the VNC password and authenticate to the Mac (no macOS account compromise is required, only the VNC password), they would be able to perform file-transfer operations, with root permissions, due to a logic flaw.</p><div class="product"><a data-dimension112="e6758530-9006-11f1-a6dc-6dab77a1e456" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure " ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6758530-9006-11f1-a6dc-6dab77a1e456" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" data-dimension25=""><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6758530-9006-11f1-a6dc-6dab77a1e456" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" data-dimension25="">View Deal</a></p></div><h2 id="drowning-in-the-ai-flood">Drowning in the AI flood</h2><p>The attacker would then be able to create new files owned by root anywhere the system allows.</p><p>In the report, the researchers demonstrated creating a valid file inside /private/etc/sudoers.d, granting passwordless sudo privileges, and once that policy was in place, they were able to run commands as root. </p><p>In a separate report, the researchers said Apple was forced to limit the number of active bug reports individual researchers can keep open at one time, due to its security teams being flooded with AI slop reports. </p><p>Since they already hit that threshold by submitting more than 50 bugs in three weeks, the researchers were unable to report this RCE flaw sooner. However, they explained that Apple reached out to Bynario directly to review, and later patch, the flaw. </p><p>The bug is now tracked as CVE-2026-43760 and was given a severity score of 8.6/10 (high). </p><p>Apple released the updates on July 27, 2026, addressing the bug on macOS Tahoe 26.6 and macOS Sonoma 14.8.8.</p><p>Those who cannot patch should disable the legacy "VNC viewers may control screen with password" option or disable Screen Sharing and Remote Management entirely.</p> </article> ]]>
Read the full article on TechRadar
Read Full Article →