Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster


Apple limited the number of vulnerabilities security researchers can submit to its bug bounty program because of an uptick in reports about fake bugs hallucinated by AI, according to The Financial Times.

bug-security-vulnerability-issue-fix-larry.jpg

Apple said its bug review system was seeing a high volume of poor-quality submissions from amateur bug hunters using AI to locate vulnerabilities. In some cases, there is no actual vulnerability, and real submissions are lost in the deluge.

The Financial Times learned of the limit after cybersecurity startup Bynario used ChatGPT to locate more than 50 macOS bugs in three weeks. Bynario found a privilege escalation exploit that could let an attacker get unrestricted access to a Mac, but was unable to report it because Apple limited the number of bug reports Bynario could submit. Bynario sent eight reports to Apple in 2025, and another five in 2026 before hitting a restriction.

Bynario's founder said it is a "very difficult time in the industry" because companies are being "flooded by the sheer amount of bugs." Apple has since been in contact with Bynario and is reviewing the company's submissions.

While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability.

AI has overwhelmed Apple because it primarily uses humans to check reports, but Apple too has turned to AI for parsing submissions. AI has also helped Apple find a huge number of bugs. Apple's recent iOS 26.6 update fixes almost 90 security vulnerabilities, some of which are credited to Anthropic's Claude and OpenAI's Codex Security.

Apple's bug bounty program offers rewards up to $2 million for exploit chains used for sophisticated, real-world attacks, plus bonuses that can increase rewards to over $5 million. Apple boosts reward totals for bugs found in betas and for bugs that bypass Lockdown Mode.

Article Link: Apple Limits Bug Bounty Submissions After Flood of AI Slop
 
Maybe that’s why iOS 27 beta 5 is delayed 😳 more than 14 days is worrisome or that beta 5 has been a total nightmare with them for some reason? I have felt beta 4 wasn’t as good as the earlier ones.
 
  • Like
Reactions: Pezola_89
Maybe they just “can’t / don’t want too” fix as many bugs being submitted..

Maybe but I suspect the AI slop argument is valid. As an example I was recently monitoring the discord for a large, open source project as a debugger.

At least once a day some 'genuis' would come in with patch requests. The (overworked) maintainers would look at a line of code and ask something technical that only a human would know like 'why did you choose this coding convention'? They'd then immediately respond with a 3 page essay defending an indefensible point (as if they're the expert rather than the project's maintainer). The reply would then be a blunt 'I don't have time to review AI slop'.
 
It COULD be possible to have "Good" hackers (ones that are hired by companies making the hardware/software) to hack into their hardware/software in order to find any bugs or major software inconsistencies. GM has already done something like that.
 
Maybe that’s why iOS 27 beta 5 is delayed 😳 more than 14 days is worrisome or that beta 5 has been a total nightmare with them for some reason? I have felt beta 4 wasn’t as good as the earlier ones.

considering they've been chasing at least one major modem issue* in the OS27 track, who knows what the holdup is.

*("more than 10" reported feedback - US carrier (Verizon), all international roaming on LTE and 5G (both SA and non-SA) fail, 3G fallback is barely available. The modem refuses to do foreign carrier auth for some reason.)
 
Well, for one (as far as I know of), sometimes the "Bug" that AI shares would be false, or technically impossible to become a "Bug". Or there would be mass-reports of "Bugs" that have already been patched.
I’ve yet to see any evidence this is why Apple limited it. Additionally, if we apply this logic, Apple’s own use should be classified as “AI slop,” which is just nonsensical. A more parsimonious explanation is the author prefers to use “AI slop” for most or all of what AI does and Apple can’t keep-up with the number of submissions, with AI just making identification less human-resource intensive.
 
  • Like
Reactions: iMean and OldNewMBP
Super lazy for security researchers to not actually verify these supposed vulnerabilities before submitting them.

In many cases the models are hallucinating source code that doesn’t actually exist in the project in question. You go to look for the function it reported to find out that it’s just an imaginary (but plausible-sounding) function name!

It would literally take 5 minutes of human time to do basic sanity checks on these submissions.
 
Super lazy for security researchers to not actually verify these supposed vulnerabilities before submitting them.

In many cases the models are hallucinating source code that doesn’t actually exist in the project in question. You go to look for the function it reported to find out that it’s just an imaginary (but plausible-sounding) function name!

It would literally take 5 minutes of human time to do basic sanity checks on these submissions.
I suspect that a lot of these "researchers" are newbies just looking for a quick buck. They have no idea how to verify the bug.
 
Because the bugs being reported often aren’t real. They’re imagined vulnerabilities, sometimes even in imaginary non-existing lines of source code, hallucinated by the AI.
This is interesting. I don’t see that described in the article. Can you share more information about this?
 
This is interesting. I don’t see that described in the article. Can you share more information about this?

Not specific to Apple, but here's a report from a few days ago describing the sort of slop that developers and security researchers are dealing with. Legitimate-sounding reports at first glance that even got flagged as critical vulnerabilities by NVD, NIST's security vulnerability database. But they pretty much all turned out to be bogus.

Apple will, no doubt, be suffering from similar submissions. There have been a lot of these articles recently!

https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.