11 Sources
[1]
Apple Limits Bug Bounty Submissions After a Barrage of AI Entries
Apple is limiting the number of submissions security experts can make to its Apple Security Bounty program. The program rewards researchers with bounties of up to $5 million for successful reporting of serious vulnerabilities in Apple's operating systems, services, or devices. Submissions can be made via Apple's dedicated portal, and there wasn't a cap on the number of submissions one could make until recently. In June, Apple decided to impose a cap after receiving a barrage of AI-assisted submissions, The Financial Times reports. The exact number of allowed submissions is unclear, but there is a 30-day cool-off period for submissions, and researchers can request that Apple increase their quota if they need to report critical vulnerabilities that require the company's immediate attention. "With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once," Apple told the FT, adding that requests for additional submissions can be made at any time. The report highlighted an Italian research group's recent experience with the Apple Security Bounty program. The group, called Bynario, had discovered 50 bugs in macOS 27 with the help of ChatGPT. One of the vulnerabilities allowed attackers to gain full control of the computer, but they weren't able to submit a report to Apple about it. The group had reported eight bugs in 2025 and five this year before Apple stopped it from submitting further reports. The iPhone maker later confirmed to the FT that it is in touch with Bynario and reviewing their latest submissions. Apple has human experts to verify each bug report, but the company also uses AI to assess the urgency of reports, the FT adds.
[2]
Apple struggles to keep pace with AI 'bug' hunters
Apple has restricted the number of potentially dangerous software bugs researchers can submit to its internal security team, as it faces a deluge of reports from people using AI models to identify alleged risks. The Cupertino-based tech giant told the FT it had moved in June to limit the high volume of requests it was receiving, with its review system coming under pressure from "AI slop" reports that can hallucinate security risks in its software. Apple is grappling with an industry-wide phenomenon that has resulted in generative AI software tools transforming the cyber security arms race, with an increase in the detection of real security flaws and a wave of poor-quality submissions from amateur bug hunters using AI, the company said. The change in Apple's approach was highlighted by Italian cyber security start-up Bynario, which told the FT it had used OpenAI's ChatGPT to identify more than 50 bugs in the latest version of the MacBook operating system in just three weeks. Among them was one of the most serious types of vulnerability, a so-called privilege escalation exploit chain, which could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system. However, the start-up said it was unable to alert Apple to the vulnerability because the tech giant had limited the number of bug reports it could make. "It is a very difficult time in the industry," Bynario chief executive and co-founder Alfredo Pesoli said. "Maintainers and vendors have been flooded by the sheer amount of bugs [being found]." Apple told the FT that it was now in contact with Bynario and reviewing its submissions. The company has introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota. Each alleged security breach requires human review to confirm, although Apple is also using AI internally to help triage the massive upsurge. "With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once," Apple said in a statement. Researchers "can easily request an increase to that limit at any time to ensure critical reports reach our security teams," the company continued. Bynario, a seven-person start-up founded in Milan last year, develops defensive cyber security software. Three of its other co-founders previously worked at Hacking Team, the Italian surveillance software company whose hacking tools were leaked in a 2015 cyber attack. In 2025, Bynario reported eight vulnerabilities to Apple, one of which was patched in a software update in November. This year it said it had reported five more, before Apple's system refused further submissions. The privilege escalation exploit Bynario was unable to report is the latest example of AI exposing weaknesses in Apple's security systems, despite the company's longstanding emphasis on privacy and device security. Last September Apple announced Memory Integrity Enforcement, a security feature designed to prevent memory corruption attacks, one of the most common ways hackers compromise software. The company described it as "the most significant upgrade to memory safety in the history of consumer operating systems". Eight months later, researchers at Palo Alto-based Calif said they had found a way past the new security, having used Anthropic's Mythos to identify the first memory corruption exploit on the latest software. Unlike that attack, Bynario's exploit relied on so-called logic flaws, by manipulating trusted software into carrying out a sequence of otherwise legitimate actions in an unintended order. Pesoli estimated that an exploit of this type could fetch between $100,000 and $200,000 on the cybercriminal black market. Apple last year introduced a new bug bounty award mechanism that could pay out as much as $5mn for identifying the most serious and sophisticated category of threats to its software. Apple is also using AI to strengthen its software. In security updates released this week for its operating systems, the company credited tools from Anthropic and OpenAI with helping identify a number of vulnerabilities across its devices. The updates included around five times as many security fixes as previous release cycles, underlining how rapidly AI is reshaping both attack and defence in cyber security. The challenge for all software companies is that AI is having a "dual impact" on bug hunting, making it easier for amateur sleuths to submit speculative reports and for skilled researchers to find dangerous exploits, said Rafe Pilling, director of threat intelligence at cyber security firm Sophos. "The result is that bug bounty programmes are shifting from a problem of finding vulnerabilities to a problem of validating, prioritising and responding to them at machine speed." Additional reporting by Stephen Morris in Diablo
[3]
Apple caps bug bounty program due to deluge of AI submissions - Engadget
Apple is placing limits on how many submissions a party can make to its bug bounty program. The Financial Times confirmed that the company has made adjustments in response to an overwhelming number of AI-powered finds. Although AI can be used to find and identify programming problems, having so many submissions from those sources has overwhelmed review teams and potentially drowned out the bugs discovered by human security researchers. Apple said the changes include "a cap and a 30-day cool-off period on submissions through its internal security portal." Any users who want to go past the cap will need to submit a special request to do so. Apple isn't the only business to revise its open calls for bug hunters in response to the proliferation of AI tools. Google also overhauled its program earlier this year, emphasizing that difficult-to-solve problems earn a bigger payout than the small bugs AI can easily identify.
[4]
AI is flooding Apple with fake bug reports, and real $200K macOS exploit got lost in the noise
Serving tech enthusiasts for over 25 years. TechSpot means tech analysis and advice you can trust. Winners & losers: Generative AI has become a double-edged sword for security teams. The same technology that helps uncover and fix vulnerabilities faster than ever also makes it trivially easy to flood inboxes with dubious bug reports. That tension recently pushed Apple to change its bug bounty program in a way that ended up delaying disclosure of a genuinely serious exploit. Security researchers at Bynario recently told the Financial Times that Apple's new bug bounty policy held up its efforts to report dozens of vulnerabilities. Among them was a privilege escalation exploit worth up to $200,000 on the black market. Apple confirmed to the FT that it has since contacted Bynario, and that it capped how many reports a researcher can have open at once in response to a flood of AI-generated claims. Once a researcher hits that cap, they face a 30-day cool-off period before they can file again, though they can request a higher quota through the company's security portal at any time. The Cupertino giant is grappling with a problem that's been building for a couple of years. Curl's security team, for instance, has been sounding the alarm on AI slop since early 2024; by 2025, confirmed-vulnerability rates on its bug bounty program had fallen below 5%, down from more than 15% before the AI-slop wave hit. Enforcing bug-report quotas can backfire, though, because AI has also increased the number and quality of legitimate bug reports. Last year, Bynario's seven-person team reported eight exploits to Apple; this year, it used ChatGPT to uncover more than 50 in just three weeks. The researchers tried to report five of them to Apple, but the company's new quota system initially blocked the disclosures. One of those exploits, tracked as CVE-2026-43760, targeted a legacy code path in macOS Screen Sharing's VNC password authentication, a holdover for older VNC clients that don't use full macOS credentials. It let an authenticated VNC viewer read protected files outside its authorized scope, then escalate that into a working exploit capable of executing commands with root privileges. Notably, Bynario's researchers say the technique worked without triggering memory corruption at all, putting it outside the reach of Apple's Memory Integrity Enforcement system, which is designed specifically to catch memory-corruption attacks. The core problem is that even though Apple and other companies use AI to help sift through bug reports, verifying a submission still takes far more human time and effort than generating one does. Still, recent patches show the upside of AI-assisted bug hunting. Apple's latest security update, released in late July, addressed nearly 200 issues across iPhones, Safari, the App Store, the macOS kernel, and numerous other Apple products. Chrome's last two versions fixed more than 1,000 vulnerabilities combined - that's more than the previous 23 releases put together(!). That acceleration has already prompted Google to speed up its Chrome release cadence.
[5]
AI is flooding bug bounties. Apple caps, Microsoft pays
AI now finds software bugs faster than people can, and the programmes that pay for them are straining. In one week Microsoft paid a record $20m in bounties, Apple capped how many bugs a researcher can file, and Google repriced its rewards. All three were reacting to the same flood. AI has learned to find software bugs faster than people can, and the programmes that pay for them are straining. In a single week, the three biggest went three different ways. Microsoft paid out a record sum. Apple slammed the door on how many bugs a researcher can file. Google quietly repriced the whole thing. All three were reacting to the same flood. Microsoft paid more than $20m to 562 researchers over its latest bounty year, The Register reported, a record on both counts. A year earlier it was about $17m to 344. Microsoft blamed the "growing use of AI" in security research for the surge. But it is not a clean comparison: the company also widened what counts as a bug halfway through the year. Apple slams the door Apple went the opposite way. It placed a cap and a 30-day cool-off on submissions through its security portal, and anyone who wants to file more must make a special request. The change came because AI-powered finds had overwhelmed its review teams and were drowning out human researchers, the Financial Times reported. The cost is concrete. Security firm Bynario found a high-severity macOS flaw that let a remote attacker create files as root, then run commands as root. It could not report the bug quickly. It had already hit Apple's cap after filing 50 bugs in three weeks, it wrote. Apple reached out directly and patched it. The twist: Bynario had found the bug using AI. Google reprices the hard bugs Google took a third path. It rebuilt its Android and Chrome reward rules. Now it pays top money for the hard, novel exploits AI still cannot produce, and less for the routine ones it now can. It is retiring bonuses for techniques that "AI has made almost routine," it said. It also wants short, concrete reproducers rather than the long write-ups AI churns out. The economics break The common thread is money. Bug bounties were built around scarce human expertise, and AI has made both finding a bug and describing it cheap. The same slop is poisoning the public vulnerability database. AI is also finding real flaws at scale, and hunting bugs as fast as it files noise. For defenders, the upside is real. An AI bug-hunter helped find a master key to every database in Microsoft's Azure Cosmos DB. Anthropic's Claude turned up flaws in cryptographic algorithms that experts had missed. The problem is telling that signal from the flood. Each of the big three has now picked a different way to try, and none of them looks final.
[6]
Apple caps security bug reports amid surge in AI-generated findings
As it grapples with a surge in "AI slop" security reports, Apple has recently made changes to its bug bounty program. Here are the details. Apple limits number of open vulnerability reports Apple has confirmed to The Financial Times that it has "introduced a cap and a 30-day cool-off period on submissions through its internal security portal, requiring users to submit requests for an increased quota." Implemented in June, the changes are intended to address an industry-wide surge in bug reports, driven by increasingly powerful LLMs that can find, chain, and exploit vulnerabilities, leaving review teams struggling to keep pace with the volume of submissions. Just a few weeks ago, Apple confirmed that it was accelerating security updates in response to these AI tools, releasing fixes in iOS 26.5.2 and its counterparts that had originally been planned for last week's version 26.6 updates. In the security notes for all those systems, Apple credited researchers who used AI tools from OpenAI, Anthropic, Z.ai, and others with helping uncover several vulnerabilities. One of the teams credited in the updates was Calif.io, which said in May that it had used Anthropic's Mythos Preview model to build a working macOS kernel memory-corruption exploit on M5 silicon in just five days. The FT's report comes just days after GitHub introduced a tiered system for its own bug bounty program, aimed at curbing AI slop, while distinguishing submissions from verified security researchers. In its report, The FT tells the story of Bynario, a seven-person cybersecurity start-up that has been using recent AI tools and models to uncover vulnerabilities, had submissions blocked after reporting five bugs to Apple this year, and eight vulnerabilities last year, "one of which was patched in a software update in November." As a result of The FT's reporting, Apple is now in contact with Bynario and reviewing its findings, including a privilege-escalation exploit chain that could potentially give an attacker full control of a Mac. In a statement to The FT about the recent changes to its bug bounty program, Apple said: "With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once. [...]" The company added that researchers "can easily request an increase to that limit at any time to ensure critical reports reach our security teams." To read The FT's full report, follow this link. Worth checking out on Amazon
[7]
Apple Limits Bug Bounty Submissions After Flood of AI Slop
Apple limited the number of vulnerabilities security researchers can submit to its bug bounty program because of an uptick in reports about fake bugs hallucinated by AI, according to The Financial Times. Apple said its bug review system was seeing a high volume of poor-quality submissions from amateur bug hunters using AI to locate vulnerabilities. In some cases, there is no actual vulnerability, and real submissions are lost in the deluge. The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction. Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability. AI has overwhelmed Apple because it primarily uses humans to check reports, but Apple too has turned to AI for parsing submissions. AI has also helped Apple find a huge number of bugs. Apple's recent iOS 26.6 update fixes almost 90 security vulnerabilities, some of which are credited to Anthropic's Claude and OpenAI's Codex Security. Apple's bug bounty program offers rewards up to $2 million for exploit chains used for sophisticated, real-world attacks, plus bonuses that can increase rewards to over $5 million. Apple boosts reward totals for bugs found in betas and for bugs that bypass Lockdown Mode.
[8]
AI is finding Apple security flaws faster than Apple can sort through them
Apple has limited how many bug reports researchers can keep open as AI tools produce both genuine Mac vulnerabilities and a flood of questionable submissions Apple has capped the number of security reports researchers can keep open at once after AI bug hunting put its review process under pressure, according to the Financial Times. Some submissions describe hallucinated or purely theoretical risks. Others uncover vulnerabilities serious enough to require patches. Bynario told the FT that it found more than 50 possible macOS flaws in three weeks, including a privilege-escalation chain that could give an attacker full control of a Mac. Recommended Videos Every report still needs human verification, although Apple is now using AI to help triage the backlog. Finding possible weaknesses is getting easier. Working out which ones pose an immediate threat has become the harder job. How real are the AI-found flaws Bynario has already shown that its system can produce more than automated guesswork. Its Atlas platform used GPT-5.5 to uncover a macOS Screen Sharing flaw that let an authenticated VNC viewer access protected data and create files with root privileges. The attack required Screen Sharing or Remote Management to be enabled, along with legacy VNC password access. Apple assigned it CVE-2026-43760 and patched it in macOS Tahoe 26.6. Bynario also demonstrated how the flaw could be extended to run commands as root. That gave Apple a working exploit to investigate rather than another vague warning generated from a code scan. Why Apple needs the same AI Apple's recent security advisories credit researchers working with Claude for a kernel vulnerability. OpenAI Codex Security has also helped identify several WebKit issues. AI-assisted research is already contributing to fixes shipped for macOS and Safari. Restricting submissions too aggressively could delay useful discoveries, while leaving the gates open risks burying Apple's team under convincing-looking nonsense. The bottleneck is verification. Models can generate possible attack paths quickly, but Apple still has to reproduce the behavior, confirm the required conditions and decide how urgently it needs a fix. Can Apple keep the signal Apple has redesigned its bug bounty program around stronger evidence. Its maximum payout now exceeds $5 million for the most serious exploit chains, while Target Flags help researchers prove that a flaw reaches protected parts of the system. That gives Apple a better way to separate demonstrated exploits from automated speculation. Mac users can't solve the reporting backlog, but they can limit their exposure by installing security updates promptly. AI bug hunting is already finding flaws that reach Apple's patch queue.
[9]
Apple's AI Slop Problem Left a $200K macOS Exploit Unreported
Apple's security updates this week carried around five times as many fixes as previous cycles. Apple has capped how many vulnerability reports a researcher can file at once, after its security team was swamped by AI-generated submissions that invent flaws that do not exist, the Financial Times reported. The cap has already cost it a real one. Milan-based cybersecurity startup Bynario told the paper it used OpenAI's ChatGPT to surface more than 50 bugs in the latest version of macOS over three weeks. Among them was a privilege escalation exploit chain, a class of flaw that hands an attacker unrestricted control of a machine. Bynario could not report it, because Apple had already refused further submissions. Chief executive Alfredo Pesoli put the exploit's value on the criminal market at between $100,000 and $200,000, and said "maintainers and vendors have been flooded by the sheer amount of bugs" being uncovered. Apple told the FT it is now in contact with the firm and reviewing its work. Apple moved in June, adding a cap and a 30-day cool-off period on its security portal, with researchers required to apply for a bigger quota. Every alleged flaw still needs a human to confirm it, though Apple is using AI internally to triage the pile. Apple said it had "recently adjusted the number of new reports a researcher can have open at once," and that researchers can ask for a higher limit at any time. The same tools are working for Apple. In security updates last week, it credited Anthropic and OpenAI software with surfacing flaws, and carried roughly five times the fixes of a normal cycle, according to the FT. A "submission flood" The issue of AI bug reporting volume has grown in recent months. In May, security firm Bugcrowd, whose clients include OpenAI, said submissions through its platform more than quadrupled across three weeks in March, and that most were fake. HackerOne and Nextcloud suspended their paid programs in April, with Nextcloud saying no rewards would be paid "regardless of severity" until it found a way to filter the low-effort reports. The volume is driven by the rewards on offer, with Meta, Microsoft, Apple and Crypto.com paying out at least $58 million between them in 2025, while Apple's own top tier reaches $5 million for a single finding. At the same time, LLMs are becoming increasingly adept at spotting bugs. In March, Anthropic introduced Mythos, a cyber-focused model it initially restricted to selected technology companies, banks and researchers under Project Glasswing. Mozilla said it surfaced 271 vulnerabilities in Firefox during internal testing. In May, Vietnam-based security startup Calif said it had used a preview version to build the first public macOS kernel memory corruption exploit able to survive Memory Integrity Enforcement, the defence Apple announced last September as the biggest memory safety upgrade in the history of consumer operating systems. Calif found the bugs on April 25 and had a working exploit by May 1. Instead of filing a report, Calif carried the exploit to Apple's California headquarters in person, saying it wanted to avoid "getting buried in the submission flood" that entrants in hacking contest Pwn2Own had been caught in. Bynario tried the portal three months later and could not get in. AI crypto threats As well as hunting down threats, AI is also being used to engineer exploits in the crypto space. Coldcard wallet manufacturer Coinkite has suggested that AI was likely used to uncover a bug in its open source firmware that sat unnoticed for five years, enabling attackers to steal more than $100 million from its hardware wallets. It comes two months after Zcash disclosed that researcher Taylor Hornby, working with Claude Opus 4.8, had found two lines of code in its Orchard shielded pool that allowed undetectable counterfeiting of ZEC for four years -- prompting the privacy coin to roll out the Ironwood upgrade last month to address the vulnerability.
[10]
Apple Is So Overwhelmed With AI-Generated Bug Reports That It's Turning Away Security Threats. One Big One Almost Slipped Through the Cracks.
AI is making it harder for companies like Apple to keep up with the outside researchers hunting for bugs in their software. The company capped how many bug submissions researchers can have open at once, responding to a flood of what Apple itself calls "slop," low-quality reports where AI tools hallucinate security risks that don't actually exist. Bynario, a seven-person Italian cybersecurity startup team, found more than 50 bugs in the latest version of macOS in just three weeks, according to the Financial Times. One was serious enough that it should have been impossible to miss: a flaw that could hand an attacker full control of a Mac. Instead, Apple's own cap blocked the report before anyone there ever saw it "It is a very difficult time in the industry," said Alfredo Pesoli, Bynario's CEO and co-founder. "Maintainers and vendors have been flooded by the sheer amount of bugs." Apple told the FT it's now in contact with Bynario and reviewing the submissions, and that researchers can request a higher quota at any time. Pesoli estimated the exploit alone could fetch $100,000 to $200,000 on the black market.
[11]
Apple Introduces Bug Report Limits as AI Accelerates Vulnerability Research: Report
Every submission is still reviewed by human security experts Artificial intelligence is helping security researchers discover software vulnerabilities, and this trend appears to be creating a new challenge for Apple. The iPhone maker is now reportedly limiting the number of active security reports each researcher can have open simultaneously after a series of AI-assisted submissions have created a new challenge for the company. The AI tools are producing both genuine and false Mac vulnerabilities. Apple is said to be using AI to help prioritise incoming reports, but human experts still review them. Apple Caps Bug Reports As reported by the Financial Times, AI-generated bug reports have prompted Apple to limit security submissions. The publication, citing cybersecurity firm Bynario, states that it discovered more than 50 potential security flaws in Apple's macOS operating system within three weeks, including a privilege escalation chain that could allow attackers to take full control of a Mac. Bynario, using its Atlas security platform powered by GPT-5.5, reportedly uncovered a flaw in macOS Screen Sharing. The vulnerability allowed an authenticated Virtual Network Computing (VNC) client to access protected data and create files with root privileges under certain conditions. This attack affected systems in which Screen Sharing or Remote Management were enabled together with legacy VNC password authentication. Apple later assigned the flaw as CVE-2026-43760 and addressed it in its macOS Tahoe 26.6 update. Bynario has reportedly developed a working exploit that demonstrated how the flaw could be used to execute commands with root privileges. It reportedly submitted the exploit to Apple, helping its engineers reproduce the issue and validate a fix. These latest findings show AI's increasing role in uncovering vulnerabilities in less time. The Cupertino-based company reportedly said that researchers are using Claude and OpenAI Codex Security to find flaws in macOS and WebKit. The AI speeds up vulnerability discovery, but Apple still needs to manually verify each report before issuing a fix. Apple has reportedly revamped its bug bounty programme to speed up this verification process with rewards of over $5 million (roughly Rs. 47 crore) for the most critical exploit chains. The programme also includes Target Flags to help researchers provide stronger proof of exploits.
Share
Copy Link
Apple has imposed submission caps on its Security Bounty program after being flooded with AI-generated bug reports. Italian startup Bynario discovered over 50 macOS vulnerabilities using ChatGPT in three weeks but was blocked from reporting a critical privilege escalation exploit worth up to $200,000. The move highlights how AI tools are transforming cybersecurity research across the industry.

Apple has placed limits on how many submissions security researchers can make to its Apple Security Bounty program after being overwhelmed by AI bug reports
1
. The program, which rewards researchers with bounties of up to $5 million for reporting serious vulnerabilities in Apple's operating systems, services, or devices, implemented the changes in June 20242
. The new policy includes a cap and a 30-day cool-off period on submissions through Apple's internal security portal, though researchers can request quota increases for critical vulnerabilities requiring immediate attention1
."With the growing volume of AI-generated security submissions across the industry, we recently adjusted the number of new reports a researcher can have open at once," Apple stated
2
. The company's review system had come under pressure from what insiders describe as "AI slop" reports that can hallucinate security risks in its software2
.The consequences of these restrictions became apparent when Italian cybersecurity startup Bynario was unable to report a serious macOS vulnerability. The seven-person team had used ChatGPT to identify more than 50 bugs in macOS in just three weeks
2
. Among them was a privilege escalation exploit chain that could allow an attacker to seize full control of an Apple computer by gaining unrestricted access to the system2
.Bynario had reported eight vulnerabilities to Apple in 2025 and five more this year before the system refused further submissions
1
. The blocked exploit, tracked as CVE-2026-43760, targeted a legacy code path in macOS Screen Sharing's VNC password authentication and could execute commands with root privileges without triggering memory corruption4
. Bynario chief executive Alfredo Pesoli estimated such an exploit could fetch between $100,000 and $200,000 on the cybercriminal black market2
. Apple later confirmed it was in contact with Bynario and reviewing their latest submissions1
.Apple isn't alone in grappling with AI in cybersecurity. Microsoft paid a record $20 million to 562 researchers over its latest bounty year, up from approximately $17 million to 344 researchers the previous year
5
. Microsoft attributed the surge to the "growing use of AI" in security research5
. Google overhauled its program earlier this year, emphasizing that difficult-to-solve problems earn bigger payouts than the small bugs AI can easily identify3
. The company rebuilt its Android and Chrome reward rules to pay top money for hard, novel exploits AI still cannot produce, while reducing payments for routine ones AI now can5
.The challenge extends beyond bug bounties. Curl's security team reported that confirmed-vulnerability rates on its bug bounty program had fallen below 5%, down from more than 15% before the AI-generated submissions wave hit
4
. "It is a very difficult time in the industry," said Pesoli. "Maintainers and vendors have been flooded by the sheer amount of bugs [being found]"2
.Related Stories
AI-powered bug submissions present what Rafe Pilling, director of threat intelligence at Sophos, calls a "dual impact" on bug hunting. The technology makes it easier for amateur sleuths to submit speculative reports while enabling skilled researchers to find dangerous exploits
2
. "The result is that bug bounty programmes are shifting from a problem of finding vulnerabilities to a problem of validating, prioritising and responding to them at machine speed," Pilling explained2
.Apple's latest security update released in late July addressed nearly 200 issues across iPhones, Safari, the App Store, the macOS kernel, and numerous other Apple products
4
. The updates included around five times as many security fixes as previous release cycles, underlining how rapidly AI is reshaping both attack and defense in cybersecurity2
. Apple credited tools from Anthropic and OpenAI with helping identify vulnerabilities across its devices2
. The core problem remains that while AI-assisted bug reports can be generated quickly, verifying each submission still takes far more human time and effort, creating an asymmetry that vulnerability reporting systems are struggling to manage4
.Summarized by
Navi
[4]
[5]
22 Apr 2026•Technology

31 Jul 2026•Technology

06 Oct 2025•Technology
