Skip to content
worth noting Security

Apple restricted its bug bounty program amid a surge of AI-generated false reports, missing a serious macOS flaw

only one source so far

Apple has restricted report submissions to its bug bounty program because of a flood of AI-generated false reports. As a result, the Italian company Bynario could not report a macOS vulnerability worth up to 200 000 dollars on the black market, Financial Times reports.

According to the newspaper Financial Times, Apple has limited the number of bug reports that security researchers can submit to its bug bounty program. The reason is a flood of low-quality, AI-generated reports containing hallucinated vulnerabilities, which overwhelmed the report review process.

This restriction had a concrete consequence: the Italian startup Bynario used ChatGPT to discover a serious vulnerability in macOS that could allow an attacker to take full control of a computer. However, it could not report the vulnerability because Apple had closed submissions for further reports. According to Bynario CEO Alfredo Pesoli, such a bug would be worth 100 000 to 200 000 dollars on the black market. Apple has since contacted Bynario.

Meanwhile, according to the source, Apple itself uses AI from Anthropic and OpenAI to find vulnerabilities, and its latest update contained five times as many fixes as usual. In this context, Rafe Pilling from Sophos said that the role of bug bounty programs had shifted from finding vulnerabilities to verifying them at “machine speed”.

What changed

Why it matters

The case shows that AI-generated content poses a security risk not only as a tool for attackers, but also as a burden on defensive processes — when automatically generated reports overwhelm the report review system, genuine and dangerous vulnerabilities can slip through the cracks. For companies running bug bounty programs, this means they need to address report filtering and verification; otherwise, they risk serious bugs going unreported or ending up on the black market.

Two audiences, two different impacts

What this means

01

For individuals

Security researchers who use AI tools to find bugs risk having a genuine finding get lost among the mass of automatically generated false reports, with the program refusing to accept it before it has a chance to assess it.

What to do Security researchers should verify that a vulnerability they have found works before submitting a report, so they stand out from the mass of AI-generated false reports and their report does not go unanswered.
More practical updates →
02

For a business

Bug bounty programs face the risk that a flood of AI-generated false reports will make it impossible to triage genuine reports, causing a company to overlook a critical vulnerability with a real black-market value of hundreds of thousands of dollars.

Risks and compliance
What to decide Companies running bug bounty programs should consider introducing automated validation of reports (e.g. using AI) to reduce the risk of genuine critical vulnerabilities getting lost in the noise.
More business impacts →
AI spam security bug bounty macOS vulnerabilities

Check the original

Event sources

only one source so far · 1 publisher, 1 independent. We count feeds from the same owner only once.

1
The Decoder (daily AI news) independent context · first detected A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop