Apple is limiting some bug-bounty submissions after unvalidated AI findings increased the volume of reports in its review queue.
Introduced in June, the restriction limits how many vulnerability reports each researcher can keep open at once. Researchers who reach the undisclosed cap reportedly face a 30-day wait before filing again, although they may request capacity for additional or urgent findings.
AI tools can uncover legitimate flaws and generate convincing false alarms at similar speed. A volume-based limit may help reviewers regain control, but credible reports can be delayed alongside the junk.
AI-assisted findings still require proof
AI slop reports can look polished while relying on hallucinated, theoretical, or poorly tested findings. These submissions reach bug-bounty programs without enough evidence for reviewers to reproduce the issue or assess its impact.
Apple’s bounty guidelines require a working exploit or reliable proof of concept, numbered reproduction steps and an explanation of the security impact. Under those rules, the company can pause a researcher’s open reports for 180 days after repeated unvalidated AI submissions. More than two pauses can lead to removal from the program.
AI assistance remains eligible when researchers test and verify the findings. Recent security advisories credit work involving Anthropic’s Claude and OpenAI’s Codex Security, adding to evidence that AI-assisted vulnerability research can produce valid discoveries.
A valid Mac flaw hits the submission cap
Financial Times brought the restrictions to public attention after Milan-based security startup Bynario reached its open-report limit. Its seven-person team said ChatGPT helped identify more than 50 potential macOS issues in three weeks.
One finding involved macOS Screen Sharing and could expose protected data or create files with root privileges when legacy Virtual Network Computing password authentication was enabled, according to the startup. Quota restrictions initially prevented the firm from filing the report. Apple later contacted the researchers and investigated the flaw.
An official macOS Tahoe 26.6 advisory credits Bynario founder Alfredo Pesoli and two other researchers for CVE-2026-43760. A companion macOS Sonoma 14.8.8 advisory lists the same fix.
High-risk reports need a route around the cap
A 30-day wait may be too long when a blocked report includes evidence of a high-risk vulnerability.
Expedited review based on reproducibility and researcher history could help Apple identify credible exceptions without reopening its queue to automated dumping. GitHub, for example, uses researcher track records to set initial bounty access, demonstrating how submission privileges can account for a contributor’s past work.
Researchers blocked by the cap should explain the urgency when requesting additional capacity and preserve a complete disclosure timeline.
Mac administrators do not need an emergency response to the submission policy itself. Fleet owners should confirm current macOS updates are installed, review Screen Sharing and legacy VNC authentication on systems awaiting patches, and avoid delays when applying security fixes.
Also read: Lasso found that changing an AI agent’s harness can produce major differences in red teaming outcomes.





