HeadlinesBriefing favicon HeadlinesBriefing.com

Apple Bug Bounty Cap: Wrong Move in AI Era

9to5Mac •
×

Apple recently confirmed it has capped the number of open vulnerability reports that researchers can submit through its portal, with a 30-day cool-down period once you hit that cap. The reason is that a surge in AI-generated bug reports is flooding the review pipeline. I understand the instinct, but I think it’s the wrong response at exactly the wrong moment.

Apple says this is an industry-wide problem, and they are not wrong. LLMs are now fast (and good) at discovering vulnerabilities in ways humans could never do, and review teams everywhere are struggling to keep pace with the volume. However, a Financial Times report also tells the story of Bynario, a seven-person startup that had its submissions blocked after reporting five bugs to Apple this year and eight in 2025, one of which was patched in November.

Apple is now reviewing Bynario’s findings, including a privilege-escalation exploit chain that could give an attacker full control of a Mac, but this is why Apple shouldn’t cap it.