logo

Apple Bug Bounty Limits AI Slop and Fake Reports

ID: 1d9089e8-0a92-5819-8b38-f0bce079c55c

STIX ID: report--1d9089e8-0a92-5819-8b38-f0bce079c55c

Feed Name: securityonline.info

Threat Score
50/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Do Son

...
...

The report explains that mass-produced, low-quality AI-generated vulnerability submissions have overwhelmed Apple’s bug intake process, prompting the company to limit the number of open reports per researcher and impose a 30-day cooling-off period; this policy unintentionally blocked a legitimate, high-severity macOS privilege vulnerability reported by Bynario until media attention forced Apple to engage and remediate it. The story highlights consequences for triage efficiency, the risk of burying critical disclosures, and notes that other vendors (Google, GitHub) are also adjusting reward mechanisms while continuing to use AI to assist in security review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.