HeadlinesBriefing favicon HeadlinesBriefing.com

AI Slop Floods Apple's Bug Bounty Program

AppleInsider •
×

AI-generated security reports are overwhelming Apple's bug bounty system, forcing the company to limit submissions. The influx includes 'AI slop'—hallucinated reports that appear valid but are fabricated. Apple confirmed to the Financial Times it imposed caps to manage the volume, as each report requires human validation.

Legitimate researchers like Bynario, which discovered 50 macOS bugs in three weeks, face delays due to submission limits. Apple's 30-day cool-off period and allowances for higher limits aim to balance throughput, but amateurs continue submitting unchecked AI reports. While Apple uses AI to triage submissions and detect threats via tools like Claude Mythos, human oversight remains critical.

The lucrative bounty system—worth millions—ensures continued amateur participation despite AI-induced challenges. Apple is adapting, but containment remains difficult short-term. The problem highlights AI's dual role as both a security tool and a source of systemic strain.