Apple Caps Vulnerability Submissions Amid AI-Generated Spam Surge
Apple restricts simultaneous vulnerability reports due to AI-generated spam. Researchers can request higher limits. One firm missed reporting 50+ macOS flaws, citing the cap.
Woofun AI reports that Apple has restricted the number of vulnerability reports a single researcher can submit simultaneously. The company cited a surge in AI-generated submissions, many lacking genuine flaws, as the primary driver. Researchers may request higher limits at any time, while Apple employs internal AI for triage. Bynario, a Milan-based startup, discovered over 50 macOS vulnerabilities using ChatGPT within three weeks but could not report them due to the cap. CEO Alfredo Pesoli valued one privilege escalation chain at $100,000 to $200,000. Apple contacted Bynario to review the work. In June, Apple introduced a submission cap and a 30-day cooldown. Recent updates noted fixes for vulnerabilities found with Anthropic and OpenAI assistance, totaling five times the normal cycle volume.
Comments
No comments yet.