Apple caps AI-generated security bug reports amid low-quality flood
Apple has introduced a quota limiting the number of open security bug reports each researcher can maintain, adding a 30‑day reflection period. The change follows an influx of AI‑generated submissions, many of which contain hallucinated or purely theoretical flaws, overwhelming Apple’s security teams. Researchers, including the Italian firm Bynario, reported more than 50 macOS vulnerabilities in three weeks using AI tools such as ChatGPT and GPT‑5.5, uncovering serious issues like a privilege‑escalation chain (CVE‑2026‑43760) that was patched in macOS Tahoe 26.6. Apple now uses AI to triage the backlog but still requires human verification for every report. The bug‑bounty program has been restructured to demand stronger evidence, with maximum payouts exceeding $5 million for the most critical exploits. Apple says researchers can request higher limits when needed, aiming to balance the benefits of AI‑assisted discovery with the need to filter out low‑quality noise.
The policy shift was reported by the Financial Times and echoed across multiple tech outlets, highlighting a broader industry challenge as AI tools accelerate vulnerability discovery while also generating a surge of speculative reports.
Entities: Alfredo Pesoli · Apple Inc. · Bynario · Financial Times · GPT‑5.5