• A potentially dangerous macOS security flaw went unreported due t

    From TechnologyDaily@1337:1/100 to All on Tue Aug 4 12:30:26 2026
    A potentially dangerous macOS security flaw went unreported due to Apple
    being deluged by AI slop bug reports

    Date:
    Tue, 04 Aug 2026 11:25:00 +0000

    Description:
    Security researchers found a high-severity RCE flaw, which Apple later fixed.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Bynario disclosed CVE202643760, a macOS RCE flaw allowing root file creation via legacy VNC password option Apple patched it July 27, 2026 in macOS Tahoe 26.6 and Sonoma 14.8.8; unpatched users should disable Screen Sharing/Remote Management or the legacy VNC setting Reporting was delayed as Apple limited submissions due to AIgenerated bug report overload, but the company reached out directly to fix this issue Apple has fixed a high-severity vulnerability that allowed threat actors to execute malicious code remotely (RCE), as root, on certain macOS devices - and would have probably fixed the issue even sooner; had it not
    been flooded with AI slop vulnerability reports.

    Security researchers Bynario published an in-depth report discussing finding an RCE flaw on macOS 26.5.2 devices running on Apple Silicon M4 and M5 systems, with System Integrity Protection (SIP) enabled. According to
    Bynario, the vulnerability affects Mac devices with Screen Sharing or Remote Management enabled, and with the legacy "VNC viewers may control screen with password" option turned on. For those devices, should a threat actor obtain the VNC password and authenticate to the Mac (no macOS account compromise is required, only the VNC password), they would be able to perform file-transfer operations, with root permissions, due to a logic flaw. Latest Videos From TechRadar Watch full video here: Drowning in the AI flood The attacker would then be able to create new files owned by root anywhere the system allows.

    In the report, the researchers demonstrated creating a valid file inside /private/etc/sudoers.d, granting passwordless sudo privileges, and once that policy was in place, they were able to run commands as root. You may like Anthropic Mythos helped build a working macOS exploit in just five days
    Rapid7 observes new Palo Alto VPN flaw exploited in the wild to bypass GlobalProtect authentication Palo Alto warns of critical firewall flaw, tells users a patch is on the way

    In a separate report, the researchers said Apple was forced to limit the number of active bug reports individual researchers can keep open at one
    time, due to its security teams being flooded with AI slop reports.

    Since they already hit that threshold by submitting more than 50 bugs in
    three weeks, the researchers were unable to report this RCE flaw sooner. However, they explained that Apple reached out to Bynario directly to review, and later patch, the flaw. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features
    and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    The bug is now tracked as CVE-2026-43760 and was given a severity score of 8.6/10 (high).

    Apple released the updates on July 27, 2026, addressing the bug on macOS
    Tahoe 26.6 and macOS Sonoma 14.8.8.

    Those who cannot patch should disable the legacy "VNC viewers may control screen with password" option or disable Screen Sharing and Remote Management entirely. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/a-potentially-dangerous-macos-security- flaw-went-unreported-due-to-apple-being-deluged-by-ai-slop-bug-reports


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)