Key facts
- Apple has capped the number of open vulnerability reports a researcher can have at once.
- This cap was implemented after a surge in AI-generated submissions, many of which invent non-existent flaws.
- Cybersecurity startup Bynario used AI to identify over 50 macOS bugs in three weeks.
- Among Bynario's findings was a privilege escalation exploit chain that could give an attacker full control of a Mac.
- Bynario was unable to report the exploit because Apple had already refused further submissions due to the cap.
- The exploit's market value is estimated between $100,000 and $200,000.
- Apple's recent security updates included approximately five times more fixes than usual, with AI tools credited for surfacing some flaws.
Apple has introduced a limit on the number of open vulnerability reports a single researcher can submit, a move prompted by an influx of AI-generated submissions that often contain fabricated flaws. This policy change inadvertently led to a real, high-value macOS exploit going unreported by cybersecurity startup Bynario.
Bynario reported using OpenAI's ChatGPT to discover more than 50 bugs in the latest version of macOS within a three-week period. Among these was a critical privilege escalation exploit chain, capable of granting an attacker complete control over a Mac. However, Bynario could not submit this finding because Apple had already refused further reports from them due to the new submission cap.
Alfredo Pesoli, CEO of Bynario, estimated the exploit's value on the black market to be between $100,000 and $200,000, highlighting that "maintainers and vendors have been flooded by the sheer amount of bugs" being uncovered. Apple has since stated it is in contact with Bynario and is reviewing their findings.
The company implemented the cap and a 30-day cool-off period on its security portal in June, requiring researchers to apply for increased quotas. While human review is still necessary for every alleged flaw, Apple is utilizing AI internally for triage. Apple confirmed it has "recently adjusted the number of new reports a researcher can have open at once" and that researchers can request higher limits.
AI tools are also proving beneficial for Apple; recent security updates credited software from Anthropic and OpenAI for surfacing flaws, resulting in approximately five times the usual number of fixes. This issue of increased submission volume due to AI is a growing concern across the cybersecurity industry, with platforms like Bugcrowd, HackerOne, and Nextcloud also reporting significant increases in low-effort or fake reports.