
The Times details an Italian company called Bynario, which identified a fairly nasty-sounding privilege escalation chain that lets attackers take complete control of a Mac. The company also reported a second bug, CVE-2026-43760, a macOS Screen Sharing flaw that allowed an authenticated VNC viewer to access protected data and create files with root privileges.
Unfortunately, the hard-working research team was unable to report the first bug, as it had filed more than 50 reports in just three weeks thanks to AI. In other words, it’s possible some security researchers right now are unable to file warnings of critical vulnerabilities to Apple because the system is overwhelmed by slop.
This is not just an Apple problem
What makes this far more problematic is that it isn’t just Apple that is affected – security teams on multiple platforms are grappling with the same problem. Rafe Pilling, a security expert at Sophos, told the FT that bug bounty programs across the industry have had to shift from finding vulnerabilities to validating reports of them “at machine speed.”