Apple has imposed a limit on how many vulnerability reports a researcher can file at one time after its security team was overwhelmed by AI-generated submissions that described flaws that did not exist, the Financial Times reported.
The restriction has already blocked at least one real finding from reaching Apple through normal channels. Milan-based cybersecurity startup Bynario told the newspaper that it used OpenAI’s ChatGPT over a three-week period to surface more than 50 bugs in the latest version of macOS. One of those findings was a privilege escalation exploit chain, a type of flaw that can give an attacker unrestricted control of a machine.
A real exploit was left unreported through Apple’s portal
Bynario said it could not submit that exploit because Apple had already refused further reports from the firm. Chief executive Alfredo Pesoli told the Financial Times the exploit would be worth between $100,000 and $200,000 on the criminal market.
Pesoli said “maintainers and vendors have been flooded by the sheer amount of bugs” being uncovered. Apple told the Financial Times it is now in contact with Bynario and is reviewing the company’s work.
Apple added a cap and a 30-day cool-off period in June
Apple changed its security portal in June. The company added a cap on the number of reports a researcher can have open at once, along with a 30-day cool-off period. Researchers who want a larger allowance must apply for a higher quota.
Each alleged vulnerability still requires human confirmation, even though Apple is using AI internally to help triage the growing pile of submissions. Apple said it had “recently adjusted the number of new reports a researcher can have open at once,” and added that researchers can ask for a higher limit at any time.
The same AI tools are also helping Apple find bugs
The tension in the report is that AI is contributing to both sides of the problem. According to the Financial Times, Apple’s security updates last week credited software from Anthropic and OpenAI with surfacing flaws. The update cycle carried roughly five times as many fixes as a normal release cycle.
The rise in AI-driven bug reporting volume has become more visible in recent months. In May, security firm Bugcrowd, whose clients include OpenAI, said submissions through its platform more than quadrupled during three weeks in March, and that most of those reports were fake.
HackerOne and Nextcloud suspended their paid programs in April. Nextcloud said no rewards would be paid “regardless of severity” until it found a way to filter out low-effort submissions.
Bug bounty payouts are helping drive the flood
The incentives are large. The Financial Times said Meta, Microsoft, Apple, and Crypto.com paid out at least $58 million between them in 2025. Apple’s own top-tier reward can reach $5 million for a single finding.
At the same time, large language models are becoming more capable at identifying real weaknesses. In March, Anthropic introduced Mythos, a cyber-focused model that it initially restricted under Project Glasswing to selected technology companies, banks, and researchers. Mozilla said the model surfaced 271 vulnerabilities in Firefox during internal testing.
Another startup bypassed the portal and went to Apple in person
In May, Vietnam-based security startup Calif said it used a preview version of a model to build what it described as the first public macOS kernel memory corruption exploit able to survive Memory Integrity Enforcement. Apple introduced that defense last September and called it the biggest memory safety upgrade in the history of consumer operating systems.
Calif said it found the bugs on April 25 and had a working exploit by May 1.
Rather than file through Apple’s bug reporting system, Calif carried the exploit to Apple’s California headquarters in person. The company said it wanted to avoid “getting buried in the submission flood,” a problem it said had already affected entrants in the Pwn2Own hacking contest. Bynario tried the portal three months later and could not get through.
AI-assisted exploit work is also showing up in crypto security
The report said AI is not only being used to hunt for threats but also to engineer exploits in crypto-related systems. Coldcard wallet maker Coinkite has suggested AI was likely used to uncover a bug in its open-source firmware that went unnoticed for five years. According to the report, that flaw enabled attackers to steal more than $100 million from its hardware wallets.
It also pointed to a Zcash disclosure from two months ago. Researcher Taylor Hornby, working with Claude Opus 4.8, found two lines of code in the Orchard shielded pool that allowed undetectable counterfeiting of ZEC for four years. Zcash rolled out the Ironwood upgrade last month to address the issue.

