9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.
Apple dropped a staggering number of vulnerability patches in macOS Tahoe 26.6 last month. Plus a heap of fixes in iOS 26.6 and iPadOS 26.6. What stood out most to me was the number of credits that went to Claude, Codex, and other AI-adjacent tools and labs. The most I’ve ever seen in a single release.
Then came this week when Apple confirmed that it has capped the number of vulnerability reports a researcher can have open at once, with a 30-day cool-off period once that cap is reached.
On the surface, it looks like Apple got caught flat-footed here and started throwing up walls. It even admitted to “the growing volume of AI-generated security submissions across the industry” in its statement to the Financial Times.
However, it’s now increasingly clear that, since last year, nearly all of Apple’s rather baffling decisions around its security bug bounty program have been in preparation for this exact problem.
The changes really started in October 2025, when Apple announced what it called a “major evolution” of the Apple Security Bounty program. The headlines then boasted the program’s new $2 million top prize, which could climb north of $5 million with bonuses.
Buried in the same announcement was a new Capture the Flag-like system called Target Flags, built for bug hunters to better prove the depth of an exploit. Reports submitted with Target Flags can be processed programmatically, meaning they can be validated without a human reviewer.
For the researcher, this means a faster payday. Awards could be processed as soon as the bug is received and verified, even before a patch ships.
In hindsight, this was the first clear sign of Apple preparing for a wave of AI-generated reports. With Target Flags, it could split submissions into those that already prove their severity and those that need a human to sit down and check.
Then two months later, things got baffling when the floor fell out on a lot of low-hanging fruit. In December 2025, Csaba Fitzl, principal macOS security researcher at Iru, spotted a massive change in the allotted award amounts.
... continue reading