Apple's bug bounty inbox buried a real $200K macOS flaw under AI slop

Apple's bug bounty inbox buried a real $200K macOS flaw under AI slop

Apple has started capping how many bug reports security researchers can submit and enforcing a 30-day cooldown period between submissions, after a flood of low-quality, AI-generated reports with hallucinated vulnerabilities clogged its review pipeline, the Financial Times reports. Researchers who hit the cap can request a higher quota, but the mechanism still produced a real security gap: Italian startup Bynario used ChatGPT to find a serious macOS vulnerability that could give an attacker full control over a machine, then found it could not report the flaw because Apple had already blocked further submissions from it. Bynario CEO Alfredo Pesoli estimates the flaw's black-market value at $100,000 to $200,000. Apple has since reached out to Bynario, though the source does not say whether the report has since gone through or how the outreach resolved. The episode sits alongside a second, opposite use of AI at Apple: the company is using AI systems from Anthropic and OpenAI to hunt for vulnerabilities itself, and its latest updates included five times as many fixes as usual. Rafe Pilling of Sophos told the FT that bug bounty programs have shifted from finding vulnerabilities to validating them "at machine speed," raising the question of whether external bug bounty programs can survive long-term or whether large tech companies will increasingly handle vulnerability discovery in-house.

Key facts

  • Apple capped bug bounty submissions and added a 30-day cooldown after AI-generated reports with hallucinated vulnerabilities flooded its review pipeline, per the Financial Times.
  • Italian startup Bynario found a serious macOS flaw using ChatGPT but could not report it because Apple had already blocked further submissions from the company.
  • Bynario CEO Alfredo Pesoli values the flaw at $100,000 to $200,000 on the black market; Apple has since reached out to Bynario.
  • Apple itself uses AI from Anthropic and OpenAI to hunt for vulnerabilities, and its latest updates shipped five times as many fixes as usual.
  • Sophos researcher Rafe Pilling says bug bounty programs are shifting from finding vulnerabilities to validating them "at machine speed."

Why it matters

The story is a clean illustration of AI cutting both ways in security at once: the same technology that lets Apple triage and fix five times its usual volume of flaws is also the technology flooding its intake with fabricated ones, and the flood was severe enough that Apple resorted to blunt rate limiting rather than better filtering. A submission cap is a crude fix, and it caught a genuine, high-value vulnerability in its net.

Who it affects

Security researchers and startups who submit to Apple's bug bounty program now face caps and a 30-day cooldown, which can delay or block legitimate reports, as happened to Bynario. Apple users are exposed for longer to vulnerabilities that get stuck behind the cap. The dynamic also touches other companies running bug bounty programs, since the same AI-slop pressure is not unique to Apple.

How to use it

For researchers submitting to Apple's program, the practical takeaway is that hitting the submission cap is possible even with legitimate findings, and the source notes a higher quota can be requested. There is no pricing or licensing dimension to this story since it concerns a policy change to a bug bounty pipeline, not a product.

How solid is it

The account rests on Financial Times reporting relayed by The Decoder, plus a named source: Bynario CEO Alfredo Pesoli, who gives a specific dollar estimate for the flaw's value, and Sophos researcher Rafe Pilling, quoted on the shift toward validating reports "at machine speed." The source does not give a date for when Apple introduced the cap, does not quantify how many AI-generated reports triggered it, and does not confirm whether Bynario's report has since gone through.

Risks and caveats

The black-market valuation of $100,000 to $200,000 is Pesoli's own estimate, not a figure independently confirmed elsewhere in the source. Apple's outreach to Bynario is mentioned without a stated outcome, so it is not established whether the vulnerability has since been fixed or even formally reported. The broader claim that bug bounty programs may not survive long-term is framed as a question raised by the situation, not a conclusion the source draws.

“bug bounty programs have gone from finding vulnerabilities to validating them "at machine speed"”

— Rafe Pilling, Sophos