Bullish

Apple Restricts Researcher Submissions Amid AI Bug Report Surge

2026-08-02 13:42:02

Apple caps vulnerability submissions and enforces a 30-day cooldown due to AI-generated noise. Bynario found 50+ flaws, highlighting the shift from discovery to validation in bug bounty programs.

Woofun AI reports that Apple has restricted the number of vulnerability reports researchers can submit simultaneously, implementing a 30-day cool-off period since June. The company stated that a surge in AI-generated reports, some of which fabricate security risks, has strained its review system. Italian startup Bynario disclosed finding over 50 vulnerabilities in the latest MacBook OS using ChatGPT within three weeks, including a privilege escalation chain worth up to $200,000 on the black market. Although initially blocked by submission limits, Apple is now reviewing Bynario’s findings.

Apple noted that human confirmation remains required for each report, while the company uses internal AI to classify the influx. Researchers may apply for increased quotas to ensure critical issues are addressed. Recent security updates acknowledged Anthropic and OpenAI tools in discovering multiple vulnerabilities, with fixes released at five times the usual cycle speed. Sophos observed that AI enhances discovery efficiency but generates low-quality reports, shifting bug bounty challenges toward rapid validation and prioritization.

WOOFUN AI

Impact Assessment · Quick Read

Apple's policy shift reflects the operational strain caused by AI-driven bug hunting, moving the bottleneck from discovery to verification. This trend may increase the value of high-quality, validated reports while reducing noise in bounty programs. For security firms, the ability to filter and prioritize AI-generated findings becomes a critical competitive advantage.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions