Skip to content
Tech News
← Back to articles

Apple caps security bug reports amid surge in AI-generated findings

read original more articles
Why This Matters

Apple has introduced new restrictions on its bug bounty program to manage a surge in AI-generated security reports, reflecting the growing influence of AI tools in vulnerability discovery. These changes aim to balance efficient security testing with the need to prevent overwhelming review teams, highlighting the evolving landscape of cybersecurity in the AI era. For consumers and the industry, this signifies a shift towards more sophisticated and AI-aware security practices that could impact how quickly vulnerabilities are identified and fixed.

Key Takeaways

As it grapples with a surge in “AI slop” security reports, Apple has recently made changes to its bug bounty program. Here are the details.

Apple limits number of open vulnerability reports

Apple has confirmed to The Financial Times that it has “introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota.”

Implemented in June, the changes are intended to address an industry-wide surge in bug reports, driven by increasingly powerful LLMs that can find, chain, and exploit vulnerabilities, leaving review teams struggling to keep pace with the volume of submissions.

Just a few weeks ago, Apple confirmed that it was accelerating security updates in response to these AI tools, releasing fixes in iOS 26.5.2 and its counterparts that had originally been planned for last week’s version 26.6 updates.

In the security notes for all those systems, Apple credited researchers who used AI tools from OpenAI, Anthropic, Z.ai, and others with helping uncover several vulnerabilities.

One of the teams credited in the updates was Calif.io, which said in May that it had used Anthropic’s Mythos Preview model to build a working macOS kernel memory-corruption exploit on M5 silicon in just five days.

The FT’s report comes just days after GitHub introduced a tiered system for its own bug bounty program, aimed at curbing AI slop, while distinguishing submissions from verified security researchers.

In its report, The FT tells the story of Bynario, a seven-person cybersecurity start-up that has been using recent AI tools and models to uncover vulnerabilities, had submissions blocked after reporting five bugs to Apple this year, and eight vulnerabilities last year, “one of which was patched in a software update in November.”

As a result of The FT’s reporting, Apple is now in contact with Bynario and reviewing its findings, including a privilege-escalation exploit chain that could potentially give an attacker full control of a Mac.

... continue reading