Apple Limits Bug Bounty Submissions After Flood of AI Slop - MacRumors
Skip to Content

Apple Limits Bug Bounty Submissions After Flood of AI Slop

Apple limited the number of vulnerabilities security researchers can submit to its bug bounty program because of an uptick in reports about fake bugs hallucinated by AI, according to The Financial Times.

bug security vulnerability issue fix larry
Apple said its bug review system was seeing a high volume of poor-quality submissions from amateur bug hunters using AI to locate vulnerabilities. In some cases, there is no actual vulnerability, and real submissions are lost in the deluge.

The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction.

Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions.

While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.

AI has overwhelmed Apple because it primarily uses humans to check reports, but Apple too has turned to AI for parsing submissions. AI has also helped Apple find a huge number of bugs. Apple's recent iOS 26.6 update fixes almost 90 security vulnerabilities, some of which are credited to Anthropic's Claude and OpenAI's Codex Security.

Apple's bug bounty program offers rewards up to $2 million for exploit chains used for sophisticated, real-world attacks, plus bonuses that can increase rewards to over $5 million. Apple boosts reward totals for bugs found in betas and for bugs that bypass Lockdown Mode.

Popular Stories

Apple iCloud Plus expansion hero

iCloud+ Now Includes Apple TV, Apple Arcade, and Curated Apple Music Stations in Over 100 Countries

Tuesday September 15, 2026 1:43 am PDT by
Apple today announced a new subscription initiative that turns paid iCloud+ subscriptions into a broader services bundle in more than 100 countries. In select countries, Apple says every paid iCloud+ plan, including the cheapest 50GB tier, now includes Apple TV and Apple Arcade "at no additional cost," while family sharing extends the storage, TV and Arcade access to up to five people....
Everything New Your iPhone Can Do on iOS 27 Feature 1

50 New Things Your iPhone Can Do in iOS 27 - Out Now!

Monday September 14, 2026 10:48 pm PDT by
Apple released iOS 27 this week, and despite the company's focus this year on refining its flagship operating system and nixing bugs, there are still many additional features to explore, not least of which is Apple's new context-aware Siri, re-tooled for the generative AI era. Which iPhones Support Every iOS 27 Feature? This year's major iPhone software update isn't all about AI, though,...
iOS 27 Icon iPhone

iOS 27 Available Now With These 8 New Features

Monday September 14, 2026 9:00 am PDT by
Update — 10 a.m. Pacific Time: Apple has released iOS 27. During its iPhone 18 Pro and iPhone Duo event last week, Apple announced that iOS 27 will be released widely on Monday, September 14. iOS 27 should be available around 10 a.m. Pacific Time / 1 p.m. Eastern Time today via the Settings app, under General → Software Update. Below, we have highlighted eight new features and...

Top Rated Comments

chrono1081 Avatar
6 weeks ago
AI bros ruining everything as usual.
Score: 24 Votes (Like | Disagree)
6 weeks ago
I think I’m hallucinating because this should say “Apple has released iOS Developer 27 beta 5”
Score: 18 Votes (Like | Disagree)
paulypants Avatar
6 weeks ago
AI ruins everything.
Score: 11 Votes (Like | Disagree)
6 weeks ago
And the natural response issssss……… MOAR AI everyday! 🤣
Score: 9 Votes (Like | Disagree)
Nermal Avatar
6 weeks ago

Super lazy for security researchers to not actually verify these supposed vulnerabilities before submitting them.

In many cases the models are hallucinating source code that doesn’t actually exist in the project in question. You go to look for the function it reported to find out that it’s just an imaginary (but plausible-sounding) function name!

It would literally take 5 minutes of human time to do basic sanity checks on these submissions.
I suspect that a lot of these "researchers" are newbies just looking for a quick buck. They have no idea how to verify the bug.
Score: 8 Votes (Like | Disagree)
Reason077 Avatar
6 weeks ago

If AI is finding bugs, I’m not following how that is “slop.”
Because the bugs being reported often aren’t real. They’re imagined vulnerabilities, sometimes even in imaginary non-existing lines of source code, hallucinated by the AI.
Score: 7 Votes (Like | Disagree)