Apple's AI Slop Problem Left a $200K macOS Exploit Unreported
Apple has limited how many vulnerability reports researchers can file at once and added a 30-day cool-off period because its security team was overwhelmed by AI-generated submissions, many of them fake. The policy may have blocked a real finding: Bynario said it used ChatGPT to identify more than 50 macOS bugs, including a privilege-escalation chain, but could not submit it after hitting Apple’s cap. Apple says it is now reviewing the work and allows researchers to request higher limits. The flood of low-quality reports is affecting other bug-bounty programs too, with companies like Bugcrowd, HackerOne, and Nextcloud reporting spikes in mostly bogus submissions. At the same time, AI tools are also proving useful for defenders and attackers, helping uncover real flaws in Apple software, Firefox, and crypto products.
