11 Sources
[1]
Apple Limits Bug Bounty Submissions After a Barrage of AI Entries
Apple is limiting the number of submissions security experts can make to its Apple Security Bounty program. The program rewards researchers with bounties of up to $5 million for successful reporting of serious vulnerabilities in Apple's operating systems, services, or devices. Submissions can be
[2]
Apple struggles to keep pace with AI 'bug' hunters
Apple has restricted the number of potentially dangerous software bugs researchers can submit to its internal security team, as it faces a deluge of reports from people using AI models to identify alleged risks. The Cupertino-based tech giant told the FT it had moved in June to limit the high
[3]
Apple caps bug bounty program due to deluge of AI submissions - Engadget
Apple is placing limits on how many submissions a party can make to its bug bounty program. The Financial Times confirmed that the company has made adjustments in response to an overwhelming number of AI-powered finds. Although AI can be used to find and identify programming problems, having so
[4]
AI is flooding Apple with fake bug reports, and real $200K macOS exploit got lost in the noise
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. Winners & losers: Generative AI has become a double-edged sword for security teams. The same technology that helps uncover and fix vulnerabilities faster than ever also makes it trivially easy to
[5]
AI is flooding bug bounties. Apple caps, Microsoft pays
AI now finds software bugs faster than people can, and the programmes that pay for them are straining. In one week Microsoft paid a record $20m in bounties, Apple capped how many bugs a researcher can file, and Google repriced its rewards. All three were reacting to the same flood. AI has learned
[6]
Apple caps security bug reports amid surge in AI-generated findings
As it grapples with a surge in "AI slop" security reports, Apple has recently made changes to its bug bounty program. Here are the details. Apple limits number of open vulnerability reports Apple has confirmed to The Financial Times that it has "introduced a cap and a 30-day cool-off period on
[7]
Apple Limits Bug Bounty Submissions After Flood of AI Slop
Apple limited the number of vulnerabilities security researchers can submit to its bug bounty program because of an uptick in reports about fake bugs hallucinated by AI, according to The Financial Times. Apple said its bug review system was seeing a high volume of poor-quality submissions from
[8]
AI is finding Apple security flaws faster than Apple can sort through them
Apple has limited how many bug reports researchers can keep open as AI tools produce both genuine Mac vulnerabilities and a flood of questionable submissions Apple has capped the number of security reports researchers can keep open at once after AI bug hunting put its review process under
[9]
Apple's AI Slop Problem Left a $200K macOS Exploit Unreported
Apple's security updates this week carried around five times as many fixes as previous cycles. Apple has capped how many vulnerability reports a researcher can file at once, after its security team was swamped by AI-generated submissions that invent flaws that do not exist, the Financial Times
[10]
Apple Is So Overwhelmed With AI-Generated Bug Reports That It's Turning Away Security Threats. One Big One Almost Slipped Through the Cracks.
AI is making it harder for companies like Apple to keep up with the outside researchers hunting for bugs in their software. The company capped how many bug submissions researchers can have open at once, responding to a flood of what Apple itself calls "slop," low-quality reports where AI tools
[11]
Apple Introduces Bug Report Limits as AI Accelerates Vulnerability Research: Report
Every submission is still reviewed by human security experts Artificial intelligence is helping security researchers discover software vulnerabilities, and this trend appears to be creating a new challenge for Apple. The iPhone maker is now reportedly limiting the number of active security reports
Share
Copy Link
Apple has imposed submission caps on its Security Bounty program after being flooded with AI-generated bug reports. Italian startup Bynario discovered over 50 macOS vulnerabilities using ChatGPT in three weeks but was blocked from reporting a critical privilege escalation exploit worth up to $200,000. The move highlights how AI tools are transforming cybersecurity research across the industry.

Apple has placed limits on how many submissions security researchers can make to its Apple Security Bounty program after being overwhelmed by AI bug reports
1
. The program, which rewards researchers with bounties of up to $5 million for reporting serious vulnerabilities in Apple's operating systems, services, or devices, implemented the changes in June 20242
. The new policy includes a cap and a 30-day cool-off period on submissions through Apple's internal security portal, though researchers can request quota increases for critical vulnerabilities requiring immediate attention1
."With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once," Apple stated
2
. The company's review system had come under pressure from what insiders describe as "AI slop" reports that can hallucinate security risks in its software2
.The consequences of these restrictions became apparent when Italian cybersecurity startup Bynario was unable to report a serious macOS vulnerability. The seven-person team had used ChatGPT to identify more than 50 bugs in macOS in just three weeks
2
. Among them was a privilege escalation exploit chain that could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system2
.Bynario had reported eight vulnerabilities to Apple in 2025 and five more this year before the system refused further submissions
1
. The blocked exploit, tracked as CVE-2026-43760, targeted a legacy code path in macOS Screen Sharing's VNC password authentication and could execute commands with root privileges without triggering memory corruption4
. Bynario chief executive Alfredo Pesoli estimated such an exploit could fetch between $100,000 and $200,000 on the cybercriminal black market2
. Apple later confirmed it was in contact with Bynario and reviewing their latest submissions1
.Apple isn't alone in grappling with AI in cybersecurity. Microsoft paid a record $20 million to 562 researchers over its latest bounty year, up from approximately $17 million to 344 researchers the previous year
5
. Microsoft attributed the surge to the "growing use of AI" in security research5
. Google overhauled its program earlier this year, emphasizing that difficult-to-solve problems earn bigger payouts than the small bugs AI can easily identify3
. The company rebuilt its Android and Chrome reward rules to pay top money for hard, novel exploits AI still cannot produce, while reducing payments for routine ones AI now can5
.The challenge extends beyond bug bounties. Curl's security team reported that confirmed-vulnerability rates on its bug bounty program had fallen below 5%, down from more than 15% before the AI-generated submissions wave hit
4
. "It is a very difficult time in the industry," said Pesoli. "Maintainers and vendors have been flooded by the sheer amount of bugs [being found]"2
.Related Stories
AI-powered bug submissions present what Rafe Pilling, director of threat intelligence at Sophos, calls a "dual impact" on bug hunting. The technology makes it easier for amateur sleuths to submit speculative reports while enabling skilled researchers to find dangerous exploits
2
. "The result is that bug bounty programmes are shifting from a problem of finding vulnerabilities to a problem of validating, prioritising and responding to them at machine speed," Pilling explained2
.Apple's latest security update released in late July addressed nearly 200 issues across iPhones, Safari, the App Store, the macOS kernel, and numerous other Apple products
4
. The updates included around five times as many security fixes as previous release cycles, underlining how rapidly AI is reshaping both attack and defense in cybersecurity2
. Apple credited tools from Anthropic and OpenAI with helping identify vulnerabilities across its devices2
. The core problem remains that while AI-assisted bug reports can be generated quickly, verifying each submission still takes far more human time and effort, creating an asymmetry that vulnerability reporting systems are struggling to manage4
.Summarized by
Navi
[4]
[5]
22 Apr 2026•Technology

31 Jul 2026•Technology

06 Oct 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology