Updated
Updated · Computerworld · Aug 3
Apple Caps Bug Reports After 50-Plus AI Submissions in 3 Weeks Swamp Security Teams
Updated
Updated · Computerworld · Aug 3

Apple Caps Bug Reports After 50-Plus AI Submissions in 3 Weeks Swamp Security Teams

3 articles · Updated · Computerworld · Aug 3

Summary

  • Apple imposed a quota cap and 30-day cool-off period on security submissions in June after a flood of low-quality, often duplicate AI-generated bug reports clogged its review system.
  • The company said the backlog made it harder to spot serious flaws, with some reports covering already fixed or trivial issues and trusted researchers allowed to request quota extensions.
  • One Italian firm, Bynario, said it could not file a critical Mac privilege-escalation bug after submitting more than 50 reports in three weeks using AI; it also reported macOS flaw CVE-2026-43760.
  • Apple is also using AI from Anthropic and OpenAI to triage incoming reports and fix vulnerabilities, after raising its top bug bounty to $5 million and paying more than $35 million to about 800 researchers.
  • Security experts told the Financial Times the problem extends across bug bounty programs, which are increasingly spending time validating machine-generated reports rather than finding new vulnerabilities.

Insights

Could the flood of AI-generated bug reports force tech giants to miss the very zero-day exploits that put your personal data at risk?
As AI discovers vulnerabilities faster than humans can patch them, is the traditional million-dollar bug bounty model fundamentally broken?