Apple has imposed strict new submission limits on its bug bounty portal after discovering itself overwhelmed by low-quality, AI generated vulnerability stories – lots of which have been discovered to be describing safety flaws that merely did not exist.
Based on a report within the Monetary Occasions, Apple has discovered itself dealing with a large inflow of submissions from newbie bug hunters who’ve used AI to generate plausible-sounding however fully hallucinated bug stories.
In contrast to conventional spam, AI-generated bug stories embrace code which can be syntactically appropriate, references to real API calls, and plausible-sounding technical explanations of what’s occurring.
All of that might take an Apple engineer hours of time, configuring check environments, making an attempt to duplicate flaws, solely to finally confirm {that a} flaw might not truly exist.
However the hallucinated bug report might solely have taken a couple of seconds for an newbie to generate and submit.
In response to this downside, Apple has applied “a cap and a 30-day cool-off interval on submissions” by means of its bug-reporting portal, with any customers who wished to submit additional bug stories required to submit a particular request.
The Monetary Occasions learnt concerning the Apple-imposed restrict after Italian cybersecurity startup Bynario developed a customized AI scanning device constructed on GPT-5.5 that submitted a burst of greater than 50 macOS bug stories inside simply three weeks. Beforehand, with out the help of AI, Bynario had filed solely 13 bug stories throughout 2025 and early 2026.
Bynario discovered it had routinely triggered Apple’s self-imposed restrict on bug report submissions, and have been locked out of the reporting portal simply as they uncovered a crucial zero day flaw in macOS that might give attackers full root management over a pc.
Bynario chief government and co-founder Alfredo Pesoli instructed the Monetary Occasions that the exploit might fetch between US $100,000 and $200,000 on the pc underground.
Apple has since had particulars of the flaw efficiently submitted to it, however the very actual concern is that real critical bug stories will not be acquired by the corporate because of the measures it has put in place to keep away from poor-quality AI slop stories.
Sarcastically, Apple itself is actively utilizing AI to seek out vulnerabilities in its code. Its iOS 26.6 and macOS Tahoe 26.6 updates mounted round 100 safety flaws, crediting AI fashions from Anthropic and OpenAI in addition to their very own inner AI triage instruments.
Apple isn’t the one firm attempting to cope with a deluge of automated AI-generated vulnerability stories, submitted within the hope of receiving beneficiant bounties.
GitHub, as an example, lately launched a tiered bug bounty system particularly designed to filter out AI slop, by establishing an invite-only VIP group of verified researchers and limiting public submissions.
The fear is that if reporting safety holes in software program turns into too irritating for vulnerability researchers they could begin weighing up their choices. It’s all the time preferable for a bug to be reported on to the software program developer relatively than a third-party exploit dealer.
A 3rd-party exploit dealer is more likely to provide upfront money payouts for accepted submissions, with no caps on what number of exploits are submitted, and no cool-off intervals.
Worst of all, they may haven’t any qualms about promoting particulars of a vulnerability to somebody who is perhaps desiring to abuse it.
