Joseph, that is the way system was designed to work originally.
System checked by file resolution. If resolution is "allowed" one, registration is completed. If file was of incorrect format, system just displays default avatar image. Other users will not be able to see this file, download it or do anything with it.
If you think that this somehow effect your site security, let me know. I will need to have more info on how this can effect your site to check with developers.
Regarding users bypassing approval.
Are you referring to the fact that unapproved users are displayed in your newsfeed activity and under "members" section of your site?