Apple has introduced a cap on the number of vulnerabilities security researchers can submit to its Bug Bounty program, a direct response to the surge in fake bugs generated by artificial intelligence. According to the Financial Times, Apple's review system is being overwhelmed by low-quality submissions from amateur bug hunters who use AI to identify flaws that in many cases do not exist. This deluge risks burying genuine reports, posing a real threat to user security. The company's decision to rely primarily on human reviewers has made the system particularly vulnerable to automated noise, but Apple has also deployed AI tools to parse incoming submissions, showing a dual approach.
The Bynario case and the privilege escalation exploit on macOS
The news came to light after the experience of cybersecurity startup Bynario, which used ChatGPT to find more than 50 bugs in macOS within three weeks. During this activity, the company discovered a privilege escalation vulnerability that could have allowed an attacker to gain unrestricted access to a Mac. However, when Bynario tried to report the find, it discovered it had exceeded the maximum number of allowed submissions. After sending eight reports in 2025 and another five in 2026, the company hit a restriction that prevented it from submitting further bugs. Bynario's founder described this as a "very difficult time in the industry," with companies "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing its submissions.
Sponsored Protocol
The cap on reports and the option to request an increase
With this new policy, Apple has set a limit on the number of open submissions each researcher can have at any given time. However, as the company clarified, researchers can request an increase to ensure that the security team does not miss a critical vulnerability. While this measure helps filter out AI-generated noise, it might also discourage legitimate researchers who fear their most important findings will not be considered in time. Apple's reliance on human reviewers has made the system susceptible to the flood of automated reports, but the company has also implemented AI tools to analyze incoming submissions, demonstrating a dual approach.
Sponsored Protocol
AI as a double-edged sword in bug discovery
Artificial intelligence, however, is not just a problem. Apple has acknowledged that AI has helped discover a huge number of real bugs. For instance, the recent iOS 26.6 update addresses almost 90 security vulnerabilities, some of which are credited to Anthropic's Claude and OpenAI's Codex Security. This shows how AI can be a valuable ally in cybersecurity, but also how it can generate false positives if used without proper oversight. Apple's Bug Bounty program offers rewards up to $2 million for exploit chains used in sophisticated real-world attacks, with bonuses that can push the total above $5 million. Additionally, Apple boosts rewards for bugs found in betas and for those that bypass Lockdown Mode, a feature designed for at-risk users.
Sponsored Protocol
This situation raises important questions about the future of vulnerability research and the role of AI in an increasingly complex field. Apple's decision to limit reports may be seen as a necessary measure to maintain order, but it also signals the times: the technology that should help us protect systems is creating new challenges. For a deeper look at Apple's security strategies and its latest hardware innovations, check out our article on Apple prototypes 6.4-inch display for iPhone 20 Pro. If you are interested in how AI is changing the cybersecurity landscape, you might also enjoy our piece on a new free-to-play FPS blending two gaming worlds. Finally, to stay updated on the latest device trends, do not miss our guide to the best cordless vacuums of 2026.
Source: https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai