Apple Slams the Door on Bug Submissions After AI Floods the Queue 🐛🚪
Apple has capped the number of vulnerability reports a single researcher can file at once after its security team was overwhelmed by AI-generated submissions describing flaws that do not exist, the Financial Times reported. The cap has already cost the company a real find. Milan-based cybersecurity startup Bynario said it used OpenAI's ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks. Among them was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine. Bynario could not report it because Apple had already refused further submissions. Chief executive Alfredo Pesoli valued the exploit at between $100,000 and $200,000 on the criminal market and said "maintainers and vendors have been flooded by the sheer amount of bugs" being uncovered. Apple told the FT it is now in contact with the firm and reviewing its work.
In June, Apple added the cap and a 30-day cool-off period on its security portal, with researchers required to apply for a larger quota, and every alleged flaw still requiring a human to confirm it, though Apple is using AI internally to triage submissions. Apple said it had "recently adjusted the number of new reports a researcher can have open at once," and that researchers can ask for a higher limit at any time. In security updates last week, Apple credited Anthropic and OpenAI software with surfacing flaws and carried roughly five times the fixes of a normal cycle, according to the FT.
The problem extends beyond Apple. In May, security firm Bugcrowd, whose clients include OpenAI, said submissions through its platform more than quadrupled across three weeks in March and that most were fake. HackerOne and Nextcloud suspended their paid programs in April, with Nextcloud saying no rewards would be paid "regardless of severity" until it found a way to filter low-effort reports. The volume is driven by the payouts on offer, with Meta, Microsoft, Apple and Crypto.com paying at least $58 million between them in 2025, while Apple's own top tier reaches $5 million for a single finding.
At the same time, the same tools are proving useful. In March, Anthropic introduced Mythos, a cyber-focused model it initially restricted to selected technology companies, banks and researchers under Project Glasswing, and Mozilla said it surfaced 271 vulnerabilities in Firefox during internal testing.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.