Apple caps vulnerability submissions as AI-driven security reports surge

Apple caps vulnerability submissions as AI-driven security reports surge

N
News Editor
2026-08-02 05:42:02
Apple has restricted how many vulnerability reports researchers can submit at the same time after a sharp rise in AI-assisted findings put pressure on its internal review process, according to the Financial Times. The company said some AI-generated reports invent security risks, forcing its security team to spend more time filtering submissions. In June, Apple introduced a limit on concurrent submissions and added a 30-day cooling-off period, while still allowing researchers to request higher caps for serious issues. Italian cybersecurity startup Bynario said it used OpenAI’s ChatGPT to find more than 50 vulnerabilities in the latest MacBook operating system within three weeks, including a privilege-escalation attack chain that could give an attacker full control of an Apple computer. Bynario said Apple’s submission cap temporarily prevented it from filing the bugs, though Apple later said it had contacted the company and begun reviewing the reports. Apple also said every report still requires human verification, even as it uses AI internally to help classify the growing volume. The company’s latest security update disclosed that tools from Anthropic and OpenAI helped identify multiple device flaws, with the number of fixes in this cycle running at about five times a typical update period.

Apple has limited the number of vulnerability reports researchers can submit at one time after its internal security team was hit with a wave of AI-assisted filings, the Financial Times reported on Aug. 2. The company put the restriction in place in June and added a 30-day cooling-off period.

Apple said some AI-generated reports fabricate security risks, adding strain to its review system. The company said each security submission still needs human confirmation, while Apple also uses AI internally to sort the rising volume of reports. Researchers can apply for a higher submission allowance so severe bugs can still reach the security team.

Bynario says ChatGPT found more than 50 bugs in three weeks

Italian cybersecurity startup Bynario said it used OpenAI’s ChatGPT to identify more than 50 vulnerabilities in the latest MacBook operating system over a three-week period. The company said the findings included a privilege-escalation attack chain that could allow an attacker to gain full system control of an Apple computer.

Bynario said Apple’s submission limits at one point prevented the company from filing the bugs. Apple said it has now contacted Bynario and started reviewing the reports.

Bounty payouts and the latest security update

Bynario estimated that the privilege-escalation flaw it found could be worth $100,000 to $200,000 on the cybercrime black market.

Apple introduced a new bug bounty payout structure last year. Under that framework, the company can pay as much as $5 million for the most severe and most complex classes of threats found in its software.

Apple’s system security update released this week also said tools from Anthropic and OpenAI helped uncover multiple device vulnerabilities. The number of fixes in this round was about five times the level seen in a typical update cycle.

Sophos says the bottleneck has shifted

Security firm Sophos said AI is boosting the discovery of genuine vulnerabilities while also producing a large volume of low-quality reports. In bug bounty programs, the harder task is shifting away from finding flaws and toward verifying, prioritizing, and responding to them quickly.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.