Apple Caps Bug Bounty Submissions as AI Bug Reports Overwhelm Security Teams

Reviewed byNidhi Govil

11 Sources

Share

Apple has imposed submission caps on its Security Bounty program after being flooded with AI-generated bug reports. Italian startup Bynario discovered over 50 macOS vulnerabilities using ChatGPT in three weeks but was blocked from reporting a critical privilege escalation exploit worth up to $200,000. The move highlights how AI tools are transforming cybersecurity research across the industry.

News article

Apple Introduces Submission Caps on Security Bounty Program

Apple has placed limits on how many submissions security researchers can make to its Apple Security Bounty program after being overwhelmed by AI bug reports

1

. The program, which rewards researchers with bounties of up to $5 million for reporting serious vulnerabilities in Apple's operating systems, services, or devices, implemented the changes in June 2024

2

. The new policy includes a cap and a 30-day cool-off period on submissions through Apple's internal security portal, though researchers can request quota increases for critical vulnerabilities requiring immediate attention

1

.

"With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once," Apple stated

2

. The company's review system had come under pressure from what insiders describe as "AI slop" reports that can hallucinate security risks in its software

2

.

Critical MacOS Vulnerability Gets Lost in AI-Powered Bug Submissions

The consequences of these restrictions became apparent when Italian cybersecurity startup Bynario was unable to report a serious macOS vulnerability. The seven-person team had used ChatGPT to identify more than 50 bugs in macOS in just three weeks

2

. Among them was a privilege escalation exploit chain that could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system

2

.

Bynario had reported eight vulnerabilities to Apple in 2025 and five more this year before the system refused further submissions

1

. The blocked exploit, tracked as CVE-2026-43760, targeted a legacy code path in macOS Screen Sharing's VNC password authentication and could execute commands with root privileges without triggering memory corruption

4

. Bynario chief executive Alfredo Pesoli estimated such an exploit could fetch between $100,000 and $200,000 on the cybercriminal black market

2

. Apple later confirmed it was in contact with Bynario and reviewing their latest submissions

1

.

Industry-Wide Transformation of Cybersecurity Research

Apple isn't alone in grappling with AI in cybersecurity. Microsoft paid a record $20 million to 562 researchers over its latest bounty year, up from approximately $17 million to 344 researchers the previous year

5

. Microsoft attributed the surge to the "growing use of AI" in security research

5

. Google overhauled its program earlier this year, emphasizing that difficult-to-solve problems earn bigger payouts than the small bugs AI can easily identify

3

. The company rebuilt its Android and Chrome reward rules to pay top money for hard, novel exploits AI still cannot produce, while reducing payments for routine ones AI now can

5

.

The challenge extends beyond bug bounties. Curl's security team reported that confirmed-vulnerability rates on its bug bounty program had fallen below 5%, down from more than 15% before the AI-generated submissions wave hit

4

. "It is a very difficult time in the industry," said Pesoli. "Maintainers and vendors have been flooded by the sheer amount of bugs [being found]"

2

.

The Dual Impact of AI Tools in Security Research

AI-powered bug submissions present what Rafe Pilling, director of threat intelligence at Sophos, calls a "dual impact" on bug hunting. The technology makes it easier for amateur sleuths to submit speculative reports while enabling skilled researchers to find dangerous exploits

2

. "The result is that bug bounty programmes are shifting from a problem of finding vulnerabilities to a problem of validating, prioritising and responding to them at machine speed," Pilling explained

2

.

Apple's latest security update released in late July addressed nearly 200 issues across iPhones, Safari, the App Store, the macOS kernel, and numerous other Apple products

4

. The updates included around five times as many security fixes as previous release cycles, underlining how rapidly AI is reshaping both attack and defense in cybersecurity

2

. Apple credited tools from Anthropic and OpenAI with helping identify vulnerabilities across its devices

2

. The core problem remains that while AI-assisted bug reports can be generated quickly, verifying each submission still takes far more human time and effort, creating an asymmetry that vulnerability reporting systems are struggling to manage

4

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved