Apple's bug bounty program rewards researchers to report security flaws, but a flood of AI-generated reports causes problems.
(via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)
Apple decided to cap the number of bug bounty reports a researcher can have open at once. The move follows a flood of AI-generated “slop” that overwhelmed Apple’s internal security team this year.
But the cap almost backfired. A small Italian security firm had found a serious macOS flaw using ChatGPT, but they couldn’t report it because their group had already hit its new limit.
Apple bug bounty reports capped after AI floodApple’s bug bounty program pays independent security researchers to find and privately report software flaws before criminals can exploit them. Instead of selling those discoveries or publishing them immediately, researchers submit the bugs to Apple so the company can fix them and protect users.
Apple offers some of the richest rewards in the cybersecurity industry, paying anywhere from a few thousand dollars for relatively minor flaws to more than $5 million for exceptionally dangerous exploit chains that could be used in sophisticated real-world attacks. It seems all that potential cash is tempting enough to get Apple swamped with AI-generated bug reports.
The company confirmed to the Financial Times that it was forced to introduce a new cap and a 30-day cool-off period on its internal security portal back in June.
Researchers who hit their limit can request a higher quota, but the system still needs a human to review every submission despite Apple using AI to clear the backlog.
Apple told the FT it “adjusted the number of new reports a researcher can have open at once” to manage the volume.
A blocked bug worth $200,000The downside to Apple’s decision to cap reports showed up almost immediately; Bynario, a seven-person startup based in Milan, used ChatGPT to find more than 50 potential macOS bugs in three weeks.
One of them was a privilege escalation exploit chain, a serious flaw that could allow the attacker to gain full control of a Mac. But Bynario couldn’t submit it as it had already maxed out the report quota.
Apple now says it is in direct contact with Bynario and is reviewing its findings.
AI is cutting both waysApple isn’t just fighting AI slop – as the Bynario story demonstrates, AI tools are tracking down real problems. Security updates released recently credited tools from Anthropic and OpenAI, which helped uncover several vulnerabilities. Those updates included almost five times as many fixes as previous release cycles.
That’s why Apple also uses AI internally to find bugs before outsiders do.
But the flood of AI submissions is forcing a rethink of how these programs work. Instead of finding bugs, Apple’s main task has instead become quickly validating bug reports.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | How to file Apple bug reports (and why you should do it ASAP) | 5 | 7 | 24-06-2026 |
| 2 | Apple squashes iPhone security bugs with latest iOS update | 0 | 25.6 | 17-08-2026 |
| 3 | ChatGPT just learned to watch everything you do on your Mac | 0 | 23.84 | 14-08-2026 |
| 4 | GitHub revamps bug bounty program with new VIP tier, payout changes | 0 | 13.38 | 23-07-2026 |
| 5 | Apple is turning to AI companies to improve the security of its operating systems | 0 | 10.91 | 28-07-2026 |
| 6 | AI-assisted security tools are finding more bugs, but the threat level has not changed | 0 | 9.97 | 28-07-2026 |
| 7 | macOS security flaw lets hackers disable Mac protection tools without a password | -5 | 7 | 25-06-2026 |
| 8 | Apple just added a Google Cloud warning for your iPhone’s AI features | 0 | 5 | 07-07-2026 |
| 9 | Apple’s defense in AI lawsuit: Those YouTube videos were public all along | 0 | 5 | 03-07-2026 |