Apple Restricts Researcher Submissions Amid AI Bug Report Surge
Apple caps vulnerability submissions and enforces a 30-day cooldown due to AI-generated noise. Bynario found 50+ flaws, highlighting the shift from discovery to validation in bug bounty programs.
Woofun AI reports that Apple has restricted the number of vulnerability reports researchers can submit simultaneously, implementing a 30-day cool-off period since June. The company stated that a surge in AI-generated reports, some of which fabricate security risks, has strained its review system. Italian startup Bynario disclosed finding over 50 vulnerabilities in the latest MacBook OS using ChatGPT within three weeks, including a privilege escalation chain worth up to $200,000 on the black market. Although initially blocked by submission limits, Apple is now reviewing Bynario’s findings.
Apple noted that human confirmation remains required for each report, while the company uses internal AI to classify the influx. Researchers may apply for increased quotas to ensure critical issues are addressed. Recent security updates acknowledged Anthropic and OpenAI tools in discovering multiple vulnerabilities, with fixes released at five times the usual cycle speed. Sophos observed that AI enhances discovery efficiency but generates low-quality reports, shifting bug bounty challenges toward rapid validation and prioritization.
Comments
No comments yet.