EN

Apple Caps Bug Reports as AI Floods Security Review

ontime team

1- Apple limited open vulnerability submissions after AI-generated reports strained its security review system.
2- Bynario says the cap blocked a report on an exploit that could enable full computer control.
3- The surge makes validation and prioritisation a central challenge for software bug-bounty programmes.

The latest

Apple has capped the number of new security reports a researcher can keep open and imposed a 30-day cooling-off period, saying a wave of AI-assisted submissions was overwhelming its internal review process. The company told the Financial Times that generative tools were producing both genuine discoveries and low-quality reports containing hallucinated risks. Every alleged breach still requires human confirmation, although Apple is also using AI to triage the increased volume.

Details

  • Submission rules: Apple said it adjusted the limit in June to control how many reports each researcher can have open simultaneously. Researchers may request a higher quota through its internal security portal, which the company said should ensure critical findings still reach its teams. The restriction therefore applies to open cases rather than imposing an outright ban on additional submissions.
  • Bynario findings: Milan-based Bynario, a seven-person cyber security start-up founded last year, said it used OpenAI’s ChatGPT to identify more than 50 bugs in the latest version of Apple’s Mac operating system within three weeks. It reported eight vulnerabilities during 2025, including one patched in November, and five more this year before the portal rejected further submissions.
  • Exploit claim: Bynario said the blocked submission concerned a privilege-escalation exploit chain that could grant unrestricted system access and full control of an Apple computer. The claimed attack uses logic flaws to make trusted software perform legitimate actions in an unintended sequence. Apple said it had contacted Bynario and was reviewing the start-up’s reports.
  • Potential value: Bynario chief executive and co-founder Alfredo Pesoli estimated that an exploit of this type could sell for between $100,000 and $200,000 on the cybercriminal black market. The estimate has not been independently verified. Apple separately offers bug-bounty payments reaching $5 million for the most serious and sophisticated threats to its software.
  • Dual AI impact: Apple credited tools from Anthropic and OpenAI with helping uncover vulnerabilities addressed in operating-system security updates released this week. Those releases contained about five times as many fixes as previous cycles. Rafe Pilling of Sophos said AI was simultaneously helping skilled researchers find dangerous exploits and enabling amateurs to generate speculative reports.

Background

Apple announced Memory Integrity Enforcement last September, describing it as the most significant consumer operating-system memory-safety upgrade. Eight months later, researchers said they had used Anthropic’s Mythos to identify a memory-corruption exploit that bypassed the protection. Bynario’s claimed exploit differs because it relies on logic flaws rather than corrupting memory.

What’s next

Apple’s review of Bynario’s submissions is the next concrete test. Confirmation of the privilege-escalation chain, its appearance in security release notes, or a related software patch will indicate whether the capped portal can process critical reports without delaying remediation.

 

What to read next