Apple imposes limits on AI-generated security reports, FT says
Apple has capped bug bounty submissions after AI-assisted researchers flooded its review queue
Apple's bug bounty programme has a new problem, and it isn't a lack of researchers finding flaws; it's too many of them, moving faster than humans can check their work.
FT reports that Apple introduced a cap on submissions and a 30-day cool-off period for researchers utilising its Feedback Assistant tool due to a flood of AI-enabled vulnerabilities.
Not all of them represent either hallucinations or theoretical threats, while some are legitimate and can be fixed. The trouble is in discerning between them.
Italian cybersecurity firm Bynario claims its Atlas platform, powered by GPT-5.5, discovered a macOS Screen Sharing vulnerability which allowed an authenticated VNC viewer to gain access to protected data as well as create files with root privileges. Apple has assigned this bug CVE-2026-43760 and fixed it in macOS Tahoe 26. 6.
Furthermore, Bynario reported 50+ vulnerabilities in just 3 weeks, including a privilege escalation chain which could enable an attacker complete control of a Mac computer.
The trade-off is real. Bynario has said it found a separate serious vulnerability but couldn't submit it because Apple had already blocked further reports, with the flaw's black-market value estimated at up to $200,000.
Apple's own defence increasingly relies on the same technology causing the flood. Recent security advisories have credited researchers working with Claude for identifying a kernel vulnerability, while OpenAI's Codex Security tool has helped surface several WebKit issues.
To sharpen the signal further, Apple has raised its top bug bounty past $5 million for the most severe exploit chains and introduced "target flags", which let researchers prove a flaw actually reaches protected parts of the system rather than just theorising about it.
-
US politician slams Sam Altman over 'accept some bad things happening' remark
-
Italy antitrust regulator opens investigation into AI music startup Suno
-
Smart glasses face bans over privacy concerns: Full list of countries
-
Mistral AI new model beats Chinese competitors in cybersecurity, claims CEO
-
UK regulator probes Meta over child safety risks in Instagram's 'Instants' feature
-
OpenAI admits ‘not good enough’ response to Australia government hacks
-
Meta, TikTok and X challenge UK watchdog over safety data: What to know
-
Norway proposes temporary ban on AI glasses in public spaces over privacy fears