HeadlinesBriefing favicon HeadlinesBriefing.com

Apple Caps AI Bug Reports in Bounty Program

9to5Mac •
×

Apple has implemented a cap and 30-day cool-off period on security vulnerability submissions through its internal portal, effective June, to manage a surge in AI-generated reports. The company confirmed the changes to the Financial Times, noting researchers can request increased quotas as needed. This follows an industry-wide increase in bug reports driven by powerful LLMs capable of finding and chaining vulnerabilities.

Apple recently accelerated security updates in iOS 26.5.2, crediting researchers using AI tools from OpenAI, Anthropic, and Z.ai. One credited team, Calif.io, used Anthropic's Mythos Preview model to build a macOS kernel memory-corruption exploit on M5 silicon in five days. The FT reported on Bynario, a seven-person cybersecurity startup whose submissions were blocked after reporting multiple vulnerabilities.

Apple is now reviewing Bynario's findings, including a privilege-escalation exploit chain. GitHub also introduced a tiered bug bounty system to distinguish verified researchers from AI-generated submissions. Apple stated the adjustments ensure critical reports reach security teams while managing volume from AI-generated content.