AI-Generated Bug Reports Drown Apple's Bounty Program, Delaying Critical macOS Fix
Apple limits the number of bug reports security researchers can submit and enforces a 30-day cooldown period after a deluge of low-quality, AI-generated submissions floods its bug bounty inbox. The hallucinated vulnerability reports overwhelm Apple's review pipeline, making it difficult for legitimate security findings to get through. While researchers can request higher submission quotas, the cap creates real consequences for security discovery.
Italian startup Bynario discovers this problem firsthand when it uses ChatGPT to identify a serious macOS vulnerability that allows attackers full control of a machine. Because Apple blocks further submissions under the new cap policy, Bynario cannot report the flaw through normal channels. CEO Alfredo Pesoli estimates the vulnerability's black-market value at $100,000 to $200,000 before Apple eventually reaches out to the company directly.
The situation raises broader questions about the future of bug bounty programs as AI-generated reports swamp traditional submission systems. Rafe Pilling of Sophos notes that bug bounty programs shift from finding vulnerabilities to validating them "at machine speed." Meanwhile, Apple itself uses AI from Anthropic and OpenAI to hunt for vulnerabilities internally, and its latest updates include five times as many fixes as usual, suggesting big tech companies may eventually handle vulnerability discovery on their own.