Apple Caps Bug Bounty Submissions as AI-Generated Fake Reports Flood System
Executive Briefing
- Limits imposed after amateur researchers used AI to generate hallucinated vulnerability reports, burying legitimate submissions.
- Startup Bynario discovered 50+ real macOS bugs via ChatGPT but hit Apple's submission cap before reporting a critical exploit.
- Researchers can request cap increases to ensure Apple's security team reviews genuinely critical vulnerabilities.
- Apple now uses AI itself to parse submissions; iOS 26.6 fixes ~90 vulnerabilities, some credited to Claude and OpenAI Codex.
- Bug bounty rewards reach up to $2M per exploit chain, with bonuses potentially exceeding $5M for high-severity finds.
Sponsored
Apple iPad 11-inch: A16 chip, 11-inch Model, Liquid Retina Display, 128GB, Wi-Fi 6
$319.99
Apple 2024 Mac mini Desktop Computer with M4 chip with 10‑core
$769.99
Samsung 85-Inch Class Mini LED M80H Series Samsung Vision AI Smart TV
$1747.95
Apple 2026 MacBook Neo 13-inch Laptop with A18 Pro chip
$689.99