Apple’s bug bounty process is facing a problem that shows a less obvious side of AI risk in cybersecurity. The issue is not only that AI can help find vulnerabilities. It can also flood the people who review them with reports that are not useful, not real, or not ready for action.
According to the Financial Times, Apple is capping how many bug reports security researchers can submit and is enforcing a 30-day cooldown period. The reason is a surge of low-quality, AI-generated reports containing hallucinated vulnerabilities, which is clogging the review pipeline.
Why Apple is limiting bug bounty submissions
Bug bounty programs depend on a simple exchange: outside researchers find flaws, report them, and wait for the company to verify the issue. That model becomes harder to operate when the volume of incoming reports grows faster than the ability to review them.
The source article says Apple is responding by placing a cap on submissions and applying a 30-day cooldown period. Researchers can request a higher quota, but the default limit still changes the rhythm of vulnerability reporting.
The underlying pressure is AI-generated bug reporting. Tools can produce plausible-looking security claims at high speed, but the article says many of these reports include hallucinated vulnerabilities. That means reviewers must spend time separating genuine issues from noise before they can act on real risk.
For a security team, the cost is not only inconvenience. A crowded review queue can delay attention to the reports that actually matter. A cap may reduce noise, but it can also slow down researchers who have legitimate findings.
A real macOS vulnerability hit the limit
The clearest example in the source involves Italian startup Bynario. The company used ChatGPT to find a serious macOS vulnerability that could give attackers full control over a machine. But Bynario could not report it because Apple had blocked further submissions.
CEO Alfredo Pesoli estimates the flaw’s black-market value at $100,000 to $200,000. That estimate matters because it frames the discovery as more than a routine software bug. If a vulnerability with that potential value cannot immediately reach the company that can fix it, the submission process itself becomes part of the security story.
Apple has since reached out to Bynario. The source does not say what happened next, so the important point is narrower: a policy designed to control AI-driven noise also blocked a report that the researcher considered urgent and valuable.
The case captures the central tension. AI helped Bynario identify a meaningful macOS flaw. At the same time, other AI-generated reports appear to have contributed to the congestion that prevented the company from submitting it.
AI is now on both sides of vulnerability discovery
The situation is not simply a story about researchers using AI. Apple itself is using AI from Anthropic and OpenAI to hunt for vulnerabilities, according to the source article. Its latest updates included five times as many fixes as usual.
That creates a new balance of power in software security. If large technology companies can use AI internally to find more vulnerabilities, they may rely less on outside discovery. But if outside researchers also use AI effectively, they may continue to find important flaws that companies need to receive and validate.
Rafe Pilling of Sophos told the FT that bug bounty programs have gone from finding vulnerabilities to validating them "at machine speed." That phrase points to the real bottleneck. The discovery side can accelerate quickly when AI is involved. Validation, triage, and response still require a process that can decide what is real.
This is where bug bounty systems face their hardest test. If the process accepts everything, review teams drown in weak reports. If the process restricts submissions too tightly, strong reports may be delayed or blocked.
What the Apple case shows about AI security risk
The Apple example shows that AI can create cybersecurity risk indirectly. The danger is not limited to attackers using AI or researchers finding more bugs. It also includes operational overload: too many machine-generated claims competing for human review.
The source article identifies several moving parts in that overload:
- Low-quality, AI-generated reports with hallucinated vulnerabilities are clogging Apple’s review pipeline.
- Apple is capping bug report submissions and enforcing a 30-day cooldown period.
- Researchers can request a higher quota.
- Bynario could not report a serious macOS vulnerability because further submissions were blocked.
- Apple is also using AI from Anthropic and OpenAI to hunt for vulnerabilities.
Taken together, those facts suggest that the future of bug bounty programs may depend less on who can find vulnerabilities fastest and more on who can verify them reliably. As AI increases the pace of discovery, the value of clear, credible, reviewable reports rises.
The open question raised by the source is whether bug bounty programs can survive long-term in their current form, or whether big technology companies will handle more vulnerability discovery internally. Apple’s case does not settle that question. It does show why the answer matters.
If outside researchers remain important, companies need intake systems that can reject AI slop without shutting out serious work. If companies shift more discovery in-house, they still need ways to handle external reports when independent researchers find something real. Either way, AI has turned vulnerability reporting into a filtering problem as much as a discovery problem.