ThinkPatternGet the app
Story
TECHNOLOGY · AUG 4, 2026

Apple Patches macOS RCE Vulnerability After Submission Caps Delay Report

Apple Inc. patched a high-severity macOS vulnerability after new bug-reporting limits delayed the discovery's submission by security firm Bynario.

Apple Inc. patched a high-severity remote code execution vulnerability, tracked as CVE-2026-43760, on July 27, 2026, via macOS Tahoe 26.6 and Sonoma 14.8.8. The flaw allowed attackers to create root-owned files on macOS devices equipped with Apple Silicon M4 and M5 chips when Screen Sharing or Remote Management was enabled with legacy VNC password options.

The discovery of the bug was delayed due to a policy Apple introduced in June 2026. To combat a surge of AI-generated reports, the company implemented a 30-day cool-off period and a cap on the number of active reports an independent researcher could maintain. These limits prevented the Italian security firm Bynario from reporting the vulnerability immediately after the firm had submitted over 50 potential flaws within a three-week window.

Apple eventually contacted Bynario directly to resolve the issue and release the security update.


Reported across 4 outlets
Actors
Apple Inc.

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play