Apple has limited the number of vulnerability reports researchers can submit at one time after its internal security team was hit with a wave of AI-assisted filings, the Financial Times reported on Aug. 2. The company put the restriction in place in June and added a 30-day cooling-off period.
Apple said some AI-generated reports fabricate security risks, adding strain to its review system. The company said each security submission still needs human confirmation, while Apple also uses AI internally to sort the rising volume of reports. Researchers can apply for a higher submission allowance so severe bugs can still reach the security team.
Bynario says ChatGPT found more than 50 bugs in three weeks
Italian cybersecurity startup Bynario said it used OpenAI’s ChatGPT to identify more than 50 vulnerabilities in the latest MacBook operating system over a three-week period. The company said the findings included a privilege-escalation attack chain that could allow an attacker to gain full system control of an Apple computer.
Bynario said Apple’s submission limits at one point prevented the company from filing the bugs. Apple said it has now contacted Bynario and started reviewing the reports.
Bounty payouts and the latest security update
Bynario estimated that the privilege-escalation flaw it found could be worth $100,000 to $200,000 on the cybercrime black market.
Apple introduced a new bug bounty payout structure last year. Under that framework, the company can pay as much as $5 million for the most severe and most complex classes of threats found in its software.
Apple’s system security update released this week also said tools from Anthropic and OpenAI helped uncover multiple device vulnerabilities. The number of fixes in this round was about five times the level seen in a typical update cycle.
Sophos says the bottleneck has shifted
Security firm Sophos said AI is boosting the discovery of genuine vulnerabilities while also producing a large volume of low-quality reports. In bug bounty programs, the harder task is shifting away from finding flaws and toward verifying, prioritizing, and responding to them quickly.

