All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Apple Limits Bug Reports Amid AI-Generated Submissions

Created at 4 Aug · 1:41 PM1 source↑ Market-relevant
IN SHORT

Apple has capped the number of open vulnerability reports per researcher after being overwhelmed by AI-generated submissions that often invent non-existent flaws. This policy led to a real macOS exploit, valued at up to $200,000, going unreported by cybersecurity startup Bynario.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$200,000maximum value of macOS exploit
50macOS bugs found by Bynario
three weekstimeframe for Bynario's findings
five timesincrease in security fixes
30-daycool-off period on security portal

Who's Involved

Apple
technology company capping bug report submissions
Bynario
cybersecurity startup that found macOS exploit
Alfredo Pesoli
CEO of Bynario
OpenAI
AI company whose tools were used by Bynario
Anthropic
AI company whose tools were credited in Apple updates

↳ Why This Matters

The increasing sophistication of AI in generating exploit code poses a significant challenge for cybersecurity, potentially overwhelming bug bounty programs and allowing real vulnerabilities to go undetected or unreported, thereby increasing security risks for users.

Key facts

  • Apple has capped the number of open vulnerability reports a researcher can have at once.
  • This cap was implemented after a surge in AI-generated submissions, many of which invent non-existent flaws.
  • Cybersecurity startup Bynario used AI to identify over 50 macOS bugs in three weeks.
  • Among Bynario's findings was a privilege escalation exploit chain that could give an attacker full control of a Mac.
  • Bynario was unable to report the exploit because Apple had already refused further submissions due to the cap.
  • The exploit's market value is estimated between $100,000 and $200,000.
  • Apple's recent security updates included approximately five times more fixes than usual, with AI tools credited for surfacing some flaws.

Apple has introduced a limit on the number of open vulnerability reports a single researcher can submit, a move prompted by an influx of AI-generated submissions that often contain fabricated flaws. This policy change inadvertently led to a real, high-value macOS exploit going unreported by cybersecurity startup Bynario.

Bynario reported using OpenAI's ChatGPT to discover more than 50 bugs in the latest version of macOS within a three-week period. Among these was a critical privilege escalation exploit chain, capable of granting an attacker complete control over a Mac. However, Bynario could not submit this finding because Apple had already refused further reports from them due to the new submission cap.

Alfredo Pesoli, CEO of Bynario, estimated the exploit's value on the black market to be between $100,000 and $200,000, highlighting that "maintainers and vendors have been flooded by the sheer amount of bugs" being uncovered. Apple has since stated it is in contact with Bynario and is reviewing their findings.

The company implemented the cap and a 30-day cool-off period on its security portal in June, requiring researchers to apply for increased quotas. While human review is still necessary for every alleged flaw, Apple is utilizing AI internally for triage. Apple confirmed it has "recently adjusted the number of new reports a researcher can have open at once" and that researchers can request higher limits.

AI tools are also proving beneficial for Apple; recent security updates credited software from Anthropic and OpenAI for surfacing flaws, resulting in approximately five times the usual number of fixes. This issue of increased submission volume due to AI is a growing concern across the cybersecurity industry, with platforms like Bugcrowd, HackerOne, and Nextcloud also reporting significant increases in low-effort or fake reports.

Frequently asked questions

Apple capped bug reports due to a surge in AI-generated submissions that often invent non-existent flaws, overwhelming their security team.

Bynario found a privilege escalation exploit chain for macOS, which could grant an attacker full control of a Mac.

The exploit was estimated to be worth between $100,000 and $200,000 on the criminal market.

AI tools are enabling the rapid generation of numerous bug reports, many of which are fake, creating a 'submission flood' for security vendors.

What Happens Next

01Apple is reviewing the findings submitted by Bynario.
02Researchers can apply for higher submission quotas from Apple at any time.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Apple implemented a cap on open vulnerability reports per researcher.
Cybersecurity startup Bynario used AI to find over 50 macOS bugs in three weeks.
Bynario discovered a privilege escalation exploit chain for macOS.
Apple had refused further submissions from Bynario due to the new cap.
Bynario stated the exploit could be worth $100,000 to $200,000 on the criminal market.
Apple is now in contact with Bynario and reviewing their findings.
Security updates from Apple credited AI tools for surfacing flaws.
Other platforms like Bugcrowd, HackerOne, and Nextcloud have also seen surges in AI-generated bug reports.

Sources

T1
Apple's AI Slop Problem Left a $200K macOS Exploit UnreportedDecrypt

Related Stories

OpenAI disputes Apple's lawsuit claims, citing 'receipts'
4 Aug · 10:00 AM
Crypto firms seek access to advanced AI models for security
4 Aug · 6:16 AM
UNAM requires 58,000 students to retake remote AI-proctored exam due to widespread cheating concerns
3 Aug · 7:11 PM
Obsidian Security raises $85M at $1.1B valuation amid AI security demand
4 Aug · 12:12 PM
Apple seeks preliminary injunction against OpenAI in trade secrets case
4 Aug · 5:59 AM