Apple Caps Bug Reports After 50-Plus AI Submissions in 3 Weeks Swamp Security Teams
Updated
Updated · Computerworld · Aug 3
Apple Caps Bug Reports After 50-Plus AI Submissions in 3 Weeks Swamp Security Teams
3 articles · Updated · Computerworld · Aug 3
Summary
Apple imposed a quota cap and 30-day cool-off period on security submissions in June after a flood of low-quality, often duplicate AI-generated bug reports clogged its review system.
The company said the backlog made it harder to spot serious flaws, with some reports covering already fixed or trivial issues and trusted researchers allowed to request quota extensions.
One Italian firm, Bynario, said it could not file a critical Mac privilege-escalation bug after submitting more than 50 reports in three weeks using AI; it also reported macOS flaw CVE-2026-43760.
Apple is also using AI from Anthropic and OpenAI to triage incoming reports and fix vulnerabilities, after raising its top bug bounty to $5 million and paying more than $35 million to about 800 researchers.
Security experts told the Financial Times the problem extends across bug bounty programs, which are increasingly spending time validating machine-generated reports rather than finding new vulnerabilities.