Back to Home
AI

Apple caps bug bounty reports as AI ‘slop’ floods security team

Apple has limited bug bounty reports after AI slop overwhelmed its security team. (via Cult of Mac - Your source for the latest Apple news, rumors, analysis, reviews, how-tos and deals.)

t
tech4you AI
August 4, 20262 min read
Share

Apple decided to cap the number of bug bounty reports a researcher can have open at once. The move follows a flood of AI-generated “slop” that overwhelmed Apple’s internal security team this year.

But the cap almost backfired. A small Italian security firm had found a serious macOS flaw using ChatGPT, but they couldn’t report it because their group had already hit its new limit.

Apple bug bounty reports capped after AI flood

Apple’s bug bounty program pays independent security researchers to find and privately report software flaws before criminals can exploit them. Instead of selling those discoveries or publishing them immediately, researchers submit the bugs to Apple so the company can fix them and protect users.

Apple offers some of the richest rewards in the cybersecurity industry, paying anywhere from a few thousand dollars for relatively minor flaws to more than $5 million for exceptionally dangerous exploit chains that could be used in sophisticated real-world attacks. It seems all that potential cash is tempting enough to get Apple swamped with AI-generated bug reports.

The company confirmed to the Financial Times that it was forced to introduce a new cap and a 30-day cool-off period on its internal security portal back in June.

Researchers who hit their limit can request a higher quota, but the system still needs a human to review every submission despite Apple using AI to clear the backlog.

Apple told the FT it “adjusted the number of new reports a researcher can have open at once” to manage the volume.

A blocked bug worth $200,000

The downside to Apple’s decision to cap reports showed up almost immediately; Bynario, a seven-person startup based in Milan, used ChatGPT to find more than 50 potential macOS bugs in three weeks.

One of them was a privilege escalation exploit chain, a serious flaw that could allow the attacker to gain full control of a Mac. But Bynario couldn’t submit it as it had already maxed out the report quota.

Apple now says it is in direct contact with Bynario and is reviewing its findings.

AI is cutting both ways

Apple isn’t just fighting AI slop – as the Bynario story demonstrates, AI tools are tracking down real problems. Security updates released recently credited tools from Anthropic and OpenAI, which helped uncover several vulnerabilities. Those updates included almost five times as many fixes as previous release cycles.

That’s why Apple also uses AI internally to find bugs before outsiders do.

But the flood of AI submissions is forcing a rethink of how these programs work. Instead of finding bugs, Apple’s main task has instead become quickly validating bug reports.


Originally published on Cult of Mac

Related Articles