Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didn't exist.

According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

All of that could take an Apple engineer hours of time, configuring test environments, attempting to replicate flaws, only to ultimately verify that a flaw may not actually exist.

But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

In response to this problem, Apple has implemented "a cap and a 30-day cool-off period on submissions" through its bug-reporting portal, with any users who wished to submit further bug reports required to submit a special request.

The Financial Times learnt about the Apple-imposed limit after Italian cybersecurity startup Bynario developed a custom AI scanning tool built on GPT-5.5 that submitted a burst of more than 50 macOS bug reports within just three weeks. Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

Bynario found it had automatically triggered Apple's self-imposed limit on bug report submissions, and were locked out of the reporting portal just as they uncovered a critical zero day flaw in macOS that could give attackers full root control over a computer.

Bynario chief executive and co-founder Alfredo Pesoli told the Financial Times that the exploit could fetch between US $100,000 and $200,000 on the computer underground.

Apple has since had details of the flaw successfully submitted to it, but the very real concern is that genuine serious bug reports may not be received by the company due to the measures it has put in place to avoid poor-quality AI slop reports.

Ironically, Apple itself is actively using AI to find vulnerabilities in its code. Its iOS 26.6 and macOS Tahoe 26.6 updates fixed around 100 security flaws, crediting AI models from Anthropic and OpenAI as well as their own internal AI triage tools.

Apple is not the only company trying to deal with a deluge of automated AI-generated vulnerability reports, submitted in the hope of receiving generous bounties.

GitHub, for instance, recently introduced a tiered bug bounty system specifically designed to filter out AI slop, by establishing an invite-only VIP group of verified researchers and limiting public submissions.

The worry is that if reporting security holes in software becomes too frustrating for vulnerability researchers they may start weighing up their options. It is always preferable for a bug to be reported directly to the software developer rather than a third-party exploit broker.

A third-party exploit broker is likely to offer upfront cash payouts for accepted submissions, with no caps on how many exploits are submitted, and no cool-off periods.

Worst of all, they might have no qualms about selling details of a vulnerability to someone who might be intending to abuse it.

tags