Apple blocked a $200K macOS bug report because its bounty inbox drowned in AI slop
Curated by the Inblix editorial team
Apple’s bug bounty program has hit a wall — and it’s not sophisticated attackers causing the gridlock. The company is now capping how many reports security researchers can submit because its review pipeline is flooded with low-quality, AI-generated noise. The Financial Times reports that researchers are using tools like ChatGPT to churn out reports packed with hallucinated vulnerabilities, overwhelming the humans who triage them.
This bottleneck has real consequences. Italian startup Bynario used ChatGPT to uncover a genuine macOS flaw that could hand an attacker full control of a machine. CEO Alfredo Pesoli pegged its black-market value between $100,000 and $200,000. But when they tried to report it, they couldn’t. Apple had already blocked further submissions from them. The company did eventually reach out to Bynario, but the incident exposes a system breaking under its own weight.
Here’s the irony: Apple is simultaneously using AI — from Anthropic and OpenAI — to hunt for the very vulnerabilities its bounty program is supposed to surface. Its latest updates shipped with five times the usual number of fixes. That volume suggests internal AI tooling is finding plenty, but it also raises an uncomfortable question. If the bounty inbox is too polluted to process external reports, are companies quietly deciding they’d rather just do the work themselves?
Rafe Pilling of Sophos captured the shift bluntly, telling the FT that bug bounty programs have morphed from a mechanism for finding vulnerabilities into one for validating them “at machine speed.” That’s a fundamental redefinition of the model. A program designed to incentivize human ingenuity is now drowning in machine-generated garbage, while the same machines are being deployed to replace the humans it was meant to attract. Whether the economics of crowdsourced security can survive that contradiction is an open question — one Apple clearly doesn’t have an answer for yet.
💡 Key Takeaways
- Apple capped bug bounty submissions after its review pipeline was overwhelmed by AI-generated reports filled with hallucinated vulnerabilities, according to the Financial Times.
- A legitimate macOS exploit valued at up to $200,000 went unreported because Bynario, the startup that found it, was blocked from submitting to Apple's program.
- Rafe Pilling of Sophos noted that bug bounty programs have shifted from discovering vulnerabilities to merely validating them 'at machine speed' as companies increasingly rely on internal AI tools.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.