Apple Limits Bug Bounty Submissions After Flood of AI Slop
- Reference: 0184856838
- News link: https://it.slashdot.org/story/26/08/04/2045214/apple-limits-bug-bounty-submissions-after-flood-of-ai-slop
- Source link:
> [2]The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction.
>
> Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions. While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.
[1] https://www.macrumors.com/2026/08/04/aple-bug-bounty-limits-ai/
[2] https://www.ft.com/content/4532122d-90f2-4433-9df6-ca99d8a141d2
Bug reports with example code (Score:2)
Perhaps bug reports could be submitted with code in a specified format that could be run, like test code, and compared to an expected result, validating the bug report.
An automated review would be able to test that the behaviour has been correctly reported. This would then leave the task of determining whether the reported behaviour is correctly classified as a "bug", and further, how important that bug is.
Generally bug reports are made with a description of how to reproduce the bug, but this can require qu
smart move (Score:1)
Apple Engineer : we are getting too many bugs reported from people due to their use of AI.
Apple Exec : Easy fix let's only let them submit 5 a month.
Apple Engineer : errrr yeah sure that will fix it. rolling eyes sarcasticly.
6 months later
Apple Exec : Why the FUCK are all these bugs being released on the internet for our OS
Apple Engineer : Because you told us to not let people submit them to us....
Bynario's Flaw (Score:2)
Their system is built on symbiotic relationships, but their current behavior is swinging to parasitic. They are overwhelming their host.
They should expect to get throttled - indeed they should strategically throttle themselves. Keep to high value bugs and pace them. Expecting that the bounty well should be infinitely drawn from at max rate without consequence isn't reasonable.
Re: (Score:2)
"indeed they should strategically throttle themselves" is what one would do if only they had the knowledge but almost anyone has access to AI producing the reports so it's first come first served thus they will report early and often.
No surprise (Score:2)
AI can generate lots of bug-reports and most will be fake or low-quality. The human review needed is the actual bottleneck. And that will not go away.
Auto increase (Score:3, Interesting)
Apple should automatically increase the number of open submissions for a given researcher if they have previously accepted ones from them.
Re: (Score:1)
Nope... that won't fix the issue.
Bug bounty programs are finished/done... everything is gonna be flagged as a bug. It'll (the AIs) view users having access to root or admin as a bug and seal that off (don't worry... someone will make an AI that patches stuff in real-time, and those patches will lock you out, both at the keyboard and over the network because you're the weak point).
Remember how there used to be orders of magnitude less bugs identified in *Nix... now, there's tons identified? Thank AI.
How ma