[REVISION HISTORY]
Apple AI bug-report cap
Updated 1 time since CLSTR started tracking revisions of this situation.
What changed
2026-08-03 12:13 UTC → 2026-08-03 13:09 UTC ·
added
removed
On 2 August 2026 Apple announced introduced a limit on quota that limits the number of active open macOS security‑bug reports each researcher can maintain after maintain, adding a surge 30‑day reflection period. The move responded to an influx of AI‑generated submissions, notably from the many of which were speculative or hallucinated. Italian startup Bynario that used GPT‑5 tools such as ChatGPT and GPT‑5.5 to uncover dozens of file more than 50 potential flaws. The cap, paired with macOS flaws in three weeks, including a 30‑day reflection period privilege‑escalation chain (CVE‑2026‑43760) that was patched in macOS Tahoe 26.6. Apple now triages reports with AI but requires human verification, and a mechanism the bug‑bounty program has been restructured with payouts that can exceed $5 million for quota increases on critical exploits. Researchers may request higher limits for high‑impact findings, is intended to separate genuine vulnerabilities from speculative or hallucinated ones. findings. The next day, following day Mozilla patched released patches for a critical high‑severity remote‑code‑execution flaw (CVE‑2026‑10702) bug in the SpiderMonkey JavaScript engine with (CVE‑2026‑10702) in Firefox 151.0.3 (2 June 2026) and Tor Browser 15.0.19. The release 15.0.19 (20 July 2026). Mozilla’s notes referenced Apple’s new reporting limits, noting limits and noted that Bynario’s submissions were blocked, and blocked. Both companies urged users to update their browsers and macOS software promptly.
Versions
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.