- AI-generated reports flood Apple's security teams, overwhelming its review process and prompting the company to limit the number of open submissions an outside researcher can make.
- A real macOS flaw worth between $100,000 and $200,000 went unreported because the bug bounty inbox was filled with low-quality, AI-generated reports.
- Apple has reached out to Bynario regarding the unreported flaw, indicating a response to the situation.
- Generative AI enables faster discovery of software flaws but also complicates Apple's bug reporting system with inaccurate speculation, increasing costs for sorting real threats from noise.
- Apple uses AI from Anthropic and OpenAI to prioritize bug reports and identify vulnerabilities, contributing to more security fixes in recent updates.
- Bug bounty programs may face challenges in the long term as big tech companies consider handling vulnerability discovery independently.
- Rafe Pilling of Sophos noted that bug bounty programs have shifted from finding vulnerabilities to validating them at machine speed.
Apple is facing significant challenges in its bug reporting process as a surge of AI-generated reports has overwhelmed its security teams. The company has implemented new limits on submissions from outside researchers to manage the influx of low-quality reports, which complicates the identification of genuine vulnerabilities.12
The flood of inaccurate AI-generated reports has led to a backlog, resulting in the unreported discovery of a serious macOS flaw by Italian startup Bynario. This vulnerability, which could allow attackers full control over a machine, was valued at $100,000 to $200,000 by CEO Alfredo Pesoli. Bynario was unable to report the flaw due to Apple’s restrictions on submissions.

Apple is leveraging AI from companies like OpenAI and Anthropic to prioritize bug reports and enhance its security measures. The latest updates from Apple included five times as many fixes as usual, indicating a proactive approach to vulnerability management. However, the situation raises questions about the future of bug bounty programs, as they may struggle to adapt to the rapid pace of AI advancements in cybersecurity.9
Rafe Pilling of Sophos noted that bug bounty programs have shifted from finding vulnerabilities to validating them at “machine speed.” This evolution underscores the need for tech companies to reassess their strategies in vulnerability discovery and reporting.10
“Bynario used ChatGPT to find the macOS flaw, which CEO Alfredo Pesoli estimates is worth $100,000–$200,000, but couldn't submit it after Apple blocked reports. Apple has since reached out to Bynario, and its latest updates included five times as many fixes as usual, aided by OpenAI and Anthropic models.”
