Apple3 mins read

AI-Generated Bug Reports Are Clogging Apple’s Bug Bounty Pipeline

Apple has capped bug bounty submissions after a flood of AI-generated reports, and a serious macOS flaw was initially left unreported as a result.

Neon green Apple logo illustration
Image credits:The Decoder

The Core Problem: Too Many AI-Generated Reports

Apple’s bug bounty program is being slowed by low-quality, AI-generated vulnerability reports, according to The Decoder. The company has capped the number of reports security researchers can submit and added a 30-day cooldown period. Researchers can request a higher quota, but the new limits show how AI-generated noise can create real friction in security workflows.

A Serious macOS Flaw Got Stuck Outside the Queue

The submission limits reportedly affected Italian startup Bynario, which used ChatGPT to find a serious macOS vulnerability. The flaw could give attackers full control over a machine, but Bynario was initially unable to report it because Apple had blocked further submissions. CEO Alfredo Pesoli estimated the flaw’s black-market value at $100,000 to $200,000, and Apple has since reached out to the company.

AI Is Both the Filter Problem and the Discovery Tool

The case highlights a sharp tension for cybersecurity teams: AI can help find vulnerabilities, but it can also flood review systems with fabricated or low-value reports. Apple itself is using AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates included five times as many fixes as usual. The practical takeaway is that bug bounty programs may need stronger triage, researcher reputation systems, and clearer escalation paths for high-risk findings.

Why This Matters for Bug Bounty Programs

Bug bounty programs depend on fast, credible signal from outside researchers. If review queues fill with hallucinated submissions, real vulnerabilities can be delayed, creating avoidable security gaps. The Decoder’s report also raises a broader question: whether large tech companies will keep relying on open bug bounty pipelines or move more vulnerability discovery in-house as AI accelerates both finding and validating flaws.

Discover More