Apple and Bynario agree GPT-5.5 found a real macOS bug. They disagree on the report cap.

Apple has implemented submission caps for security researchers to manage the influx of AI-generated vulnerability reports. The policy change follows a surge in low-quality submissions, though it has sparked debate regarding the balance between automated security testing and human verification.
Why it matters
This highlights the growing tension between the efficiency of AI-assisted cybersecurity research and the capacity of human teams to verify findings.
Apple now caps how many security reports some researchers can have open at once. And once they hit that cap, they may have to wait 30 days before reporting another potentially dangerous software flaw through the company's internal security portal.
The company introduced the limitations in June after receiving a flood of AI-assisted reports, many of which turned out to be “AI slop,” meaning they were not genuine vulnerabilities. Although AI can help researchers find possible flaws and compile detailed reports, each submission still has to be reproduced and verified.
Italian cybersecurity company Bynario drew attention to the new rules after it reached the limit. According to reporting from the Financial Times , Bynario used GPT-5.5 through its Atlas platform to find more than 50 possible bugs in Apple’s latest Mac operating system in just three weeks.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in