Apple sets a limit on the number of bug reports that can be submitted in response to an influx of AI-generated reports.



AI-powered security research is leading to the discovery of software vulnerabilities at an unprecedented pace. However, this has also resulted in a surge in low-quality bug reports generated by AI, prompting Apple to implement a limit on the number of vulnerability reports that security researchers can submit to Apple's security team.

Apple struggles to keep pace with AI 'bug' hunters | FINANCIAL TIMES

https://www.ft.com/content/4532122d-90f2-4433-9df6-ca99d8a141d2

AI is finding Apple security flaws faster than Apple can sort through them - Digital Trends
https://www.digitaltrends.com/computing/ai-is-finding-apple-security-flaws-faster-than-apple-can-sort-through-them/

According to the Financial Times, Apple took measures in June 2026 to limit the number of bug reports it receives. While AI has enabled the discovery of a large number of potential issues in a shorter amount of time than before, it has also led to a large number of false positives and insufficient reports that are not vulnerabilities, which Apple has internally referred to as 'AI slop,' placing a heavy burden on Apple to review.

Similar situations are occurring frequently among security companies and development teams. Security company HackerOne and the development team of the open-source network tool cURL had been running 'bug bounty programs' that paid rewards to researchers who discovered security vulnerabilities. However, as AI has increased the speed and number of bug discoveries, their traditional operating methods have become unsustainable. In addition, they have been receiving a large number of low-quality vulnerability reports generated by AI, leading them to announce the discontinuation of their programs.

The 'Internet Bug Bounty Program' has stopped accepting new submissions due to an increase in bug detections using AI - GIGAZINE



Apple told the Financial Times that it 'reviews submitted reports and expands the per-researcher limit as needed.' There is a limit on information provided through Apple's security portal, including a 30-day grace period, and users who wish to provide additional information must apply for an increase in the limit.

In fact, Italian cybersecurity firm Bynario discovered more than 50 vulnerabilities in macOS Tahoe in just three weeks using OpenAI's ChatGPT, but explained that they were temporarily unable to submit any new reports because they had reached Apple's submission limit. Among the vulnerabilities discovered were serious issues that could lead to 'privilege escalation,' where an attacker could gain more privileges than they should.

Meanwhile, Apple itself is actively utilizing AI. The company uses AI to classify and prioritize a large volume of vulnerability reports, and has also revealed that its latest software update fixes several vulnerabilities discovered through AI-powered research.



Ruff Pilling, Director of Threat Intelligence at cybersecurity firm Sophos, said, 'The challenge for all software companies is that AI is having a 'dual impact' on bug hunting. That is, there are downsides for responding companies, as amateur researchers are more likely to submit speculative reports, and advantages, as skilled researchers are more likely to discover serious vulnerabilities. As a result, bug bounty programs are shifting from the problem of discovering vulnerabilities to the problem of verifying, prioritizing, and responding to vulnerabilities at machine speed.'

Furthermore, the technology news site Digital Trends pointed out that 'AI-powered research has already contributed to patches released for macOS and Safari,' adding that 'while excessively limiting the number of bug reports could delay valuable discoveries, accepting reports without limits risks overwhelming Apple's team with nonsensical information that only looks plausible.' The problem is that while AI's ability to discover vulnerabilities is rapidly improving, companies are not keeping pace in verifying and fixing them.

in AI,   Security, Posted by log1e_dh