Apple restricted its bug bounty program amid a surge of AI-generated false reports, missing a serious macOS flaw
Apple has restricted report submissions to its bug bounty program because of a flood of AI-generated false reports. As a result, the Italian company Bynario could not report a macOS vulnerability worth up to 200 000 dollars on the black market, Financial Times reports.
According to the newspaper Financial Times, Apple has limited the number of bug reports that security researchers can submit to its bug bounty program. The reason is a flood of low-quality, AI-generated reports containing hallucinated vulnerabilities, which overwhelmed the report review process.
This restriction had a concrete consequence: the Italian startup Bynario used ChatGPT to discover a serious vulnerability in macOS that could allow an attacker to take full control of a computer. However, it could not report the vulnerability because Apple had closed submissions for further reports. According to Bynario CEO Alfredo Pesoli, such a bug would be worth 100 000 to 200 000 dollars on the black market. Apple has since contacted Bynario.
Meanwhile, according to the source, Apple itself uses AI from Anthropic and OpenAI to find vulnerabilities, and its latest update contained five times as many fixes as usual. In this context, Rafe Pilling from Sophos said that the role of bug bounty programs had shifted from finding vulnerabilities to verifying them at “machine speed”.
Why it matters
The case shows that AI-generated content poses a security risk not only as a tool for attackers, but also as a burden on defensive processes — when automatically generated reports overwhelm the report review system, genuine and dangerous vulnerabilities can slip through the cracks. For companies running bug bounty programs, this means they need to address report filtering and verification; otherwise, they risk serious bugs going unreported or ending up on the black market.
Two audiences, two different impacts
What this means
For individuals
Security researchers who use AI tools to find bugs risk having a genuine finding get lost among the mass of automatically generated false reports, with the program refusing to accept it before it has a chance to assess it.
For a business
Bug bounty programs face the risk that a flood of AI-generated false reports will make it impossible to triage genuine reports, causing a company to overlook a critical vulnerability with a real black-market value of hundreds of thousands of dollars.
Risks and complianceCheck the original
Event sources
only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.