Apple puts a quota wall on open security reports as AI submissions surge

Apple now caps how many vulnerability reports a researcher can keep open, a move tied to the rising tide of AI-generated submissions.

AppleThreat Staff
2 Min Read

A flood of low-quality, machine-generated vulnerability reports has pushed Apple to throttle how many bug submissions one researcher can keep open. The change, in place since June, also adds a 30-day cool-off between batches, with a quota increase available on request through Apple’s internal security portal, as confirmed to the Financial Times.

Powerful language models can now scan code, chain weaknesses, and write up exploit findings faster than human reviewers can triage them. Apple still leans on people to validate every claim, and genuine discoveries risk being buried beneath hallucinations and recycled output.

The friction shows up in concrete cases. Bynario, which employs seven people, says ChatGPT helped it find more than 50 macOS bugs in three weeks, among them a privilege-escalation chain that could give an attacker full control of a Mac.

That same startup was blocked from submitting after filing eight reports in 2025 and five in 2026, and Apple has since contacted the company and is reviewing its findings. The industry is wrestling with the same problem, and GitHub rolled out a tiered bug bounty structure days earlier to separate established researchers from AI noise.

Apple’s program still pays up to $2M for exploit chains, with bonuses that can push past $5M for bugs that bypass Lockdown Mode or surface in betas. Researchers can request a higher quota at any time, Apple says, so critical reports still reach its teams. The tension is whether caps protect reviewers or quietly silence the researchers the program exists to reward.

Share This Article