Apple fights surge of questionable vulnerability reports
Want to cash in on that Apple Security Bounty program?

REUTERS/Gonzalo Fuentes
- Apple capped vulnerability reports and added a 30-day wait after receiving AI-generated, low-quality submissions.
- Bynario said it found more than 50 MacBook operating system bugs using ChatGPT within three weeks.
- One reported bug could let attackers take full control of a user’s MacBook, raising concerns about delayed reviews.
- Apple says humans review every report, but researchers worry limits may slow fixes for serious security flaws.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Apple has implemented a cap and a month-long waiting period.
Apple is limiting the number of allegedly dangerous software bugs that researchers can submit to its internal security team.
The reason for imposing these limitations is that security researchers rely on AI to identify the risks. The company started limiting submissions after receiving a high volume of reports that were actually “AI slop.”
Apple has introduced limitations and a 30-day waiting period for submissions through the company’s internal security portal.
The first to notice the limitations was an Italian cybersecurity company, Bynario.
The company has found more than 50 bugs in Apple’s latest MacBook operating systems within 3 weeks using ChatGPT, according to the Financial Times.
One of these vulnerabilities was a privilege-escalation exploit chain that would allow the attacker to gain full control of a user’s MacBook.
Bynario reported that it was unable to flag the bug due to Apple’s decision to limit reports.
Nevertheless, Apple has contacted the company to review its submissions.
Every security breach reported to Apple is reviewed by a human, even though the company uses AI to help prioritize these verifications during the surge.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Despite Apple limiting the number of open investigations a researcher can have, researchers can contact the company to request an increase in these limits.
Bynario reported 8 vulnerabilities to Apple in 2025. This year, it reported 5 more before the company began limitations.
Despite the company encouraging researchers to share any vulnerabilities, not all are being addressed in a timely manner. It was recently reported that Apple’s "Hide My Email" feature can be exploited to expose users' real email addresses.
The company has been warned about the flaw. However, it didn’t respond properly in time, thus, Tyler Murphy, a co-founder of EasyOptOuts, revealed the issue to the public.