- Apple now caps how many security reports some researchers can have open at once, with a possible 30-day wait before reporting another potentially dangerous flaw; the limits were introduced in June after a flood of AI-assisted reports, many of which turned out to be 'AI slop.'
- Bynario used GPT-5.5 through its Atlas platform and found more than 50 possible bugs in Apple’s latest Mac operating system in three weeks, including a macOS Screen Sharing flaw that could let an authenticated VNC user access protected data and create files with root privileges; Apple fixed it in macOS Tahoe 26.6.
- Bynario could not initially report the flaw because it had already hit Apple’s limit for open investigations; Apple has since reached out to Bynario to review its reports.
- Apple and Bynario agree that GPT-5.5 found a real macOS bug but disagree on the report cap introduced by Apple.
- A human reviews every security issue reported to Apple, even though Apple uses AI to sort reports when there are too many; researchers who hit the cap can ask Apple to raise it. Apple has also used the technology internally, and its latest updates contained about five times as many security fixes as previous release cycles.
- Submission caps do not distinguish convincing AI-generated reports from real security flaws found with AI, so both compete for security teams’ attention; without a reference point, the cap could hold up legitimate reports while doing little to stop convincing ones that turn out to be wrong. Security teams were already having trouble before AI caused the number of reports to jump.
- Researchers with a track record of finding real bugs could be allowed to submit more, while those using AI could be asked to prove the flaw can be reproduced.
- Researchers who repeatedly submit ineligible reports, including theoretical flaws discovered by AI without proper validation, may have their reports paused for 180 days; more than two paused periods may lead to permanent removal from the program.
- Apple has been slow to respond to real reports in the past; Murphy made the issue public after a year of back-and-forth, and Apple said it deployed a patch on July 3, 2026.
Apple and Bynario's collaboration has revealed a genuine macOS vulnerability identified by GPT-5.5, specifically a flaw in macOS Screen Sharing that could allow unauthorized access to protected data. Apple has since patched this issue in macOS Tahoe 26.6.345
However, Bynario faced challenges in reporting this flaw due to Apple’s newly implemented cap on the number of open security reports, introduced in June after a surge of AI-assisted submissions, many of which were deemed 'AI slop.' This cap requires researchers to wait 30 days before submitting another report once they reach the limit.12
Apple's policy does not differentiate between legitimate AI-generated findings and less credible reports, complicating the review process for security teams. “Without that reference point, the cap could hold up legitimate reports while doing little to stop convincing ones that turn out to be wrong,” a source noted.
The company has stated that researchers with a proven track record may be allowed to submit more reports, while those relying on AI must demonstrate reproducibility of their findings. “Researchers who repeatedly submit ineligible reports may have their submissions paused for 180 days,” Apple warned, indicating a strict approach to managing the influx of reports.13
Despite these challenges, Apple has been proactive in addressing vulnerabilities, deploying patches that included five times as many security fixes as previous cycles, although it has been criticized for slow responses to genuine reports in the past.78
“Bynario used GPT-5.5 on its Atlas platform to find more than 50 possible bugs in Apple's latest macOS in three weeks, including a Screen Sharing flaw. Apple fixed that flaw in macOS Tahoe 26.6 and has since reached out to Bynario after the cap blocked its initial report.”

