Apple and Bynario agree GPT-5.5 found a real macOS bug; they disagree on the report cap introduced after AI-generated report surge
BynarioApple Inc.

Apple and Bynario agree GPT-5.5 found a real macOS bug; they disagree on the report cap introduced after AI-generated report surge

Apple and Bynario have confirmed that GPT-5.5 identified a legitimate macOS bug, but they disagree on a new reporting cap imposed by Apple after a surge of AI-generated reports, which has complicated the submission process for genuine vulnerabilities, leading to delays in addressing real security issues.

The New Stack The New Stack4 August 2026 · 05:57 UTC
CuriousCats Full Story

Apple and Bynario's collaboration has revealed a genuine macOS vulnerability identified by GPT-5.5, specifically a flaw in macOS Screen Sharing that could allow unauthorized access to protected data. Apple has since patched this issue in macOS Tahoe 26.6.345

However, Bynario faced challenges in reporting this flaw due to Apple’s newly implemented cap on the number of open security reports, introduced in June after a surge of AI-assisted submissions, many of which were deemed 'AI slop.' This cap requires researchers to wait 30 days before submitting another report once they reach the limit.12

Apple's policy does not differentiate between legitimate AI-generated findings and less credible reports, complicating the review process for security teams. “Without that reference point, the cap could hold up legitimate reports while doing little to stop convincing ones that turn out to be wrong,” a source noted.

The company has stated that researchers with a proven track record may be allowed to submit more reports, while those relying on AI must demonstrate reproducibility of their findings. “Researchers who repeatedly submit ineligible reports may have their submissions paused for 180 days,” Apple warned, indicating a strict approach to managing the influx of reports.13

Despite these challenges, Apple has been proactive in addressing vulnerabilities, deploying patches that included five times as many security fixes as previous cycles, although it has been criticized for slow responses to genuine reports in the past.78

Key Insight
“Bynario used GPT-5.5 on its Atlas platform to find more than 50 possible bugs in Apple's latest macOS in three weeks, including a Screen Sharing flaw. Apple fixed that flaw in macOS Tahoe 26.6 and has since reached out to Bynario after the cap blocked its initial report.”
CuriousCats studied:
1
The New StackThe New Stack
Apple now caps how many security reports some researchers can have open at once. And once they hit that cap, they may have to wait 30 days before reporting another potentially dangerous software flaw through the company’s internal security portal.”
The New Stack →
Ask CuriousCats
What is the GPT-5.5's role in discovering bugs?
Why did Bynario reach out to Apple?
How does Apple's cap affect security reports?
Are there similar AI tools identifying software flaws?
How does this bug discovery compare to previous methods?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats