HeadlinesBriefing favicon HeadlinesBriefing.com

Apple AI Bug Limits

Financial Times Companies •
×

Apple has restricted the number of bug reports it can receive as AI tools flood its security team with AI‑generated submissions, creating a deluge of “AI slop” that pressures its review system.

The move was highlighted by Italian start‑up Bynario, which used Open AI’s Chat GPT to find more than 50 bugs in the latest MacBook OS in three weeks, including a serious privilege escalation exploit that could let an attacker seize full control of an Apple computer. The start‑up said it could not report the flaw because Apple limited submissions.

Apple responded by imposing a cap and a 30‑day cool‑off period on the internal security portal, allowing researchers to request a higher quota, and said it is now in contact with Bynario while using AI to triage the surge. The company noted that each report must be human‑reviewed, though AI helps prioritize.

Meanwhile, AI is reshaping the bug bounty market: Sophos director Rafe Pilling said the shift is from finding vulnerabilities to validating them at machine speed, and Apple’s bounty can pay up to $5mn for the most serious threats. Recent security updates credited tools from Anthropic and Open AI with identifying multiple flaws, showing a rapid dual impact of AI on both attack and defence. A logic‑flaw exploit estimated to fetch between $100,000 and $200,000 on the black market illustrates the high value of these findings.