A real macOS flaw worth $200K went unreported because Apple's bug bounty inbox was full of AI slop

Apple has implemented submission caps on its bug bounty program to combat a surge of low-quality, AI-generated vulnerability reports. This policy change has inadvertently blocked the reporting of a high-value macOS security flaw, sparking debate over the future of crowdsourced vulnerability discovery.
Why it matters
Illustrates the unintended consequences of AI-generated content on cybersecurity infrastructure and the potential decline of traditional bug bounty models.
AI as a cybersecurity risk, but not the way you'd think. Apple is capping the number of bug reports security researchers can submit and enforcing a 30-day cooldown period. A flood of low-quality, AI-generated reports with hallucinated vulnerabilities is clogging the review pipeline, the Financial Times reports . Researchers can request a higher quota.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in