As it grapples with a surge in “AI slop” security reports, Apple has recently made changes to its bug bounty program. Here are the details.
Apple limits number of open vulnerability reports
Apple has confirmed to The Financial Times that it has “introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota.”
Implemented in June, the changes are intended to address an industry-wide surge in bug reports, driven by increasingly powerful LLMs that can find, chain, and exploit vulnerabilities, leaving review teams struggling to keep pace with the volume of submissions.
Just a few weeks ago, Apple confirmed that it was accelerating security updates in response to these AI tools, releasing fixes in iOS 26.5.2 and its counterparts that had originally been planned for last week’s version 26.6 updates.
In the security notes for all those systems, Apple credited researchers who used AI tools from OpenAI, Anthropic, Z.ai, and others with helping uncover several vulnerabilities.
One of the teams credited in the updates was Calif.io, which said in May that it had used Anthropic’s Mythos Preview model to build a working macOS kernel memory-corruption exploit on M5 silicon in just five days.
The FT’s report comes just days after GitHub introduced a tiered system for its own bug bounty program, aimed at curbing AI slop, while distinguishing submissions from verified security researchers.
In its report, The FT tells the story of Bynario, a seven-person cybersecurity start-up that has been using recent AI tools and models to uncover vulnerabilities, had submissions blocked after reporting five bugs to Apple this year, and eight vulnerabilities last year, “one of which was patched in a software update in November.”
As a result of The FT’s reporting, Apple is now in contact with Bynario and reviewing its findings, including a privilege-escalation exploit chain that could potentially give an attacker full control of a Mac.
... continue reading