CourionAI
EN
Newsletter
← All news
security 3 min read

A real macOS flaw sat unreported because Apple's bug bounty inbox was buried in AI-written junk

Apple has capped how many bug reports each security researcher can file, because a flood of AI-generated reports with invented vulnerabilities is clogging the queue. One Italian startup could not report a genuine macOS flaw as a result.

An overflowing office in-tray buried under a toppling stack of identical blank slips, one sealed envelope trapped at the very bottom behind a closed gate

Apple has started limiting how many security reports each researcher can submit, and enforcing a 30 day cooldown afterwards, because its bug bounty inbox is drowning in AI-generated submissions that describe vulnerabilities which do not exist. The Financial Times reported the change this weekend. Researchers can ask for a higher quota, but the cap is now the default.

The side effect landed on a real flaw. Bynario, an Italian security startup, used ChatGPT to find a serious macOS vulnerability that could hand an attacker full control of a machine. When the team went to report it, they had already hit Apple’s submission limit and could not file. CEO Alfredo Pesoli estimates the flaw would fetch between 100,000 and 200,000 dollars on the grey market, where such things get sold to people who do not report them. Apple has since contacted the company directly.

There is an irony worth sitting with. While Apple throttles outside reports, it is running Anthropic and OpenAI models internally to hunt for bugs in its own code, and its most recent round of updates shipped roughly five times as many fixes as a typical release.

What is behind this. A bug bounty is a standing offer: find a security hole in our product, tell us instead of selling it, get paid. The whole system runs on human review, and review time is the scarce resource. Language models did not change what a good report looks like, they changed how cheap it is to produce something that looks like one. A fabricated vulnerability write-up can now be generated in seconds, complete with plausible technical language and a confident tone, by someone hoping a reviewer waves it through. That is what people mean by AI slop: not wrong on purpose, just produced faster than anyone can check it. Rafe Pilling of Sophos put the shift bluntly to the FT, saying bounty programmes have gone from finding vulnerabilities to validating them at machine speed. The open question is whether the model survives at all, or whether the largest companies simply pull vulnerability hunting in house and stop paying outsiders for it.

What this means for you: if you are not a security researcher, nothing on your iPhone changes today, and Apple is still shipping fixes at a healthy clip. The transferable lesson is about the shape of the problem rather than the product. Any process that depends on humans reading submissions, whether that is job applications, grant proposals, support tickets or moderation queues, is now facing the same arithmetic: generation got cheap, review did not. If you run something like that, the fix is rarely a smarter filter. It is usually a cost on the sender, a reputation signal, or a small verified channel that bypasses the flood entirely. Apple picked the first option, and a genuine flaw sat unreported for a while as the price.

Sources

Source: https://the-decoder.com/a-real-macos-flaw-worth-200k-went-unreported-because-apples-bug-bounty-inbox-was-full-of-ai-slop/

Next story

Meta gave its AI agent a second agent whose only job is remembering things

Agents on long tasks forget constraints and repeat failed commands. Meta AI's answer is a separate memory agent that keeps a structured record and decides when to interrupt with a reminder, worth up to 8 points on two benchmarks.

A long knotted rope winding into the distance beside a wooden card index box, one card lifted out and held up to the light