← All stories
● Covered by 4 sources · 4 reportsMedium impact4 neutral

Apple Implements Bug Report Caps Due to Surge in AI-Generated Submissions

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Apple capped open security reports and added a 30-day cool-off period.
  • Changes implemented in June due to a surge of AI-generated reports.
  • Many AI-assisted reports were not genuine vulnerabilities.
  • Bynario used GPT-5.5 to find macOS bug CVE-2026-43760.
  • Apple fixed CVE-2026-43760, found by Bynario via AI.

New Submission Limits for Apple's Bug Bounty Program

Apple has adjusted its bug bounty program by implementing a cap on the number of open security reports researchers can have at one time. Additionally, a 30-day cool-off period has been introduced before new submissions can be made once the cap is reached. Users can request an increased quota if needed.

Response to AI-Generated Reports

These changes, introduced in June, are a direct response to an industry-wide surge in AI-assisted security reports. Many of these submissions, described as "AI slop," were not genuine vulnerabilities, overwhelming Apple's review teams. Large Language Models (LLMs) have increased the volume of reports, making it difficult for human-discovered bugs to be prioritized.

Impact on Researchers

The new policy affected Italian cybersecurity company Bynario, which used GPT-5.5 through its Atlas platform to identify over 50 potential bugs in macOS within three weeks. One significant finding was a flaw in macOS Screen Sharing (CVE-2026-43760) that allowed authenticated VNC users to access protected data and create files with root privileges. Bynario initially faced difficulties reporting this critical bug due to the new submission limits, though Apple later assigned it a CVE and fixed it.

Broader Industry Trend

Apple is not the only company adjusting its bug bounty program in response to AI's impact. Google also revised its program earlier this year, shifting focus to prioritize more complex vulnerabilities over smaller, easily identifiable bugs that AI tools can find. Apple has previously credited researchers using AI tools from OpenAI, Anthropic, and Z.ai for uncovering vulnerabilities, accelerating security updates in iOS 26.5.2 and related systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Apple has implemented limits on vulnerability submissions to its bug bounty program after a rise in low-quality, AI-generated reports overwhelmed the system. This change impacts security researchers who use AI tools to find bugs, potentially delaying the reporting of legitimate vulnerabilities.

Apple has introduced limits on submissions to its bug bounty program, including a cap and a 30-day cool-off period, in response to an overwhelming number of AI-powered bug reports. This change aims to manage the volume of submissions and prevent human-discovered bugs from being overlooked by review teams. The adjustment reflects a broader industry trend, as Google also revised its program earlier this year to prioritize more complex vulnerabilities.

Apple has introduced a cap on open vulnerability reports and a 30-day cool-off period for submissions to its bug bounty program, citing a surge in AI-generated security findings. This change aims to manage the increased volume of reports, which has been driven by advanced large language models capable of identifying and exploiting vulnerabilities.

Apple has implemented a cap on the number of open security reports researchers can submit, a change made in June after a surge of AI-assisted reports, many of which were not genuine vulnerabilities. This policy led to Italian cybersecurity company Bynario being unable to report a critical macOS bug, CVE-2026-43760, which was later fixed by Apple.