💻
Critical macOS RCE flaw let attackers gain root access — Apple patched it July 27
💻 Technology

Critical macOS RCE flaw let attackers gain root access — Apple patched it July 27

Researchers at Bynario disclosed CVE-2026-43760, a macOS remote code execution flaw that allowed attackers to create files as root via the legacy VNC password option in Screen Sharing. Apple patched it on July 27 in macOS Tahoe 26.6 and Sonoma 14.8.8. The fix was delayed because AI-generated junk bug reports flooded Apple's submission system; Apple ultimately reached out directly to the researchers to resolve the issue. Unpatched users should disable Screen Sharing, Remote Management or the legacy VNC password setting.

Comments

No comments yet